首页> 外文会议>IEEE Conference on Communications and Network Security >Effectiveness of proactive reset for mitigating impact of stealthy attacks on networks of autonomous systems
【24h】

Effectiveness of proactive reset for mitigating impact of stealthy attacks on networks of autonomous systems

机译:积极重置的有效性,以减轻隐身攻击对自治系统网络的影响

获取原文

摘要

Recent examples have shown that sophisticated cyber attackers are capable of infiltrating the cyber defenses of major organizations and spreading stealthily through a network, potentially doing significant damage before exploited vulnerabilities can be identified or patches developed. Autonomous systems are particularly vulnerable because they are further removed from human intervention. One emerging technology designed to address this problem is proactive reset, where systems automatically undergo a reset operation that restores them to a known malware-free state, regardless of whether or not they were already infected. More frequent resets result in higher security, but may also reduce functionality of the network. In this work, we consider the effectiveness of three proactive reset policies for mitigating the spread of stealthy malware through a network of autonomous systems. We perform experiments using agent-based simulation and find that a proactive policy that uses risk-flow analysis to determine when systems should be reset achieves performance comparable to that of a perfect detector.
机译:最近的例子表明,复杂的网络攻击者能够渗透主要组织的网络防御,并通过网络悄悄地传播,可能在被识别的漏洞之前造成重大损害或者开发的补丁。自治系统特别容易受到影响,因为它们进一步从人类干预中删除。一个旨在解决此问题的新兴技术是主动重置,其中系统自动经历重置操作,该操作将其恢复到已知的恶意软件状态,无论它们是否已被感染。更频繁的复位导致安全性更高,但也可能降低网络的功能。在这项工作中,我们考虑通过自治系统网络减轻隐身恶意软件的扩散的三个主动重置政策的有效性。我们使用基于代理的模拟执行实验,并发现使用风险流分析来确定何时复位系统的主动策略实现与完美探测器的性能相当的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号