论文标题

关于在攻击建模形式主义中移动目标防御的推理

Reasoning about Moving Target Defense in Attack Modeling Formalisms

论文作者

Ballot, Gabriel, Malvone, Vadim, Leneutre, Jean, Borde, Etienne

论文摘要

自2009年以来,移动目标防御(MTD)已成为防御机制的新范式,该机制经常改变目标系统的状态,使攻击者混淆。这种频繁的变化是昂贵的,并且导致误导攻击者和破坏服务质量之间的权衡。在面对现实的多步攻击方案时,优化MTD激活频率对于开发此防御机制是必要的。基于DAG的攻击建模形式主义被显着指定这些情况。我们的贡献是一种基于DAG的新型形式主义,及其将其转化为价格定时的马尔可夫决策过程,以找到针对攻击者的时间/成本最佳策略的最佳激活频率。首次在基于DAG的最新表示中分析了MTD激活频率。此外,这是第一篇在攻击建模形式主义的自动分析中考虑MTD的特异性的论文。最后,我们使用Uppaal Stratego提出了一些实验结果,以证明其适用性和相关性。

Since 2009, Moving Target Defense (MTD) has become a new paradigm of defensive mechanism that frequently changes the state of the target system to confuse the attacker. This frequent change is costly and leads to a trade-off between misleading the attacker and disrupting the quality of service. Optimizing the MTD activation frequency is necessary to develop this defense mechanism when facing realistic, multi-step attack scenarios. Attack modeling formalisms based on DAG are prominently used to specify these scenarios. Our contribution is a new DAG-based formalism for MTDs and its translation into a Price Timed Markov Decision Process to find the best activation frequencies against the attacker's time/cost-optimal strategies. For the first time, MTD activation frequencies are analyzed in a state-of-the-art DAG-based representation. Moreover, this is the first paper that considers the specificity of MTDs in the automatic analysis of attack modeling formalisms. Finally, we present some experimental results using Uppaal Stratego to demonstrate its applicability and relevance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源