1.College of command and control engineering, Army Engineering University of PLA, Nanjing 210007, Jiangsu, China
2.National Key Laboratory of Science and Technology on Information System Security, Academy of Military Sciences PLA China, Beijing 100141, Beijing, China
Moving target defense (MTD) is a game-changing technique providing a proactive method against advanced persistent threats (APT) in cybersecurity. Although partial MTD techniques have been employed in several systems, the research of optimization for strategies is still stalled in single layer and single parameter, which hinders the world-wide application multilayer MTD technology. Focused on the MTD strategy optimization, the basic model of MTD and the influence of diverse parameters is analyzed from system view, while the model for the process of service-reconfiguration is established in this paper. Based on the Markov decision process (MDP), the MTD strategy optimization model is presented, and the Q-learning algorithm is introduced, which solves the strategy selection and state explosion of MTD. Finally, with the assessment model, a case study is given to illustrate the method by calculating the optimal strategy that can balance the system availability and security, which could guide the deployment of MTD in the future.
在仿真实验中,本文构建如图3所示的网络拓扑结构,并在其中部署了相应的MTD技术,对每个MTD技术优化重配置周期和空间这两个参数,具体攻防参数如表1和表2所示,本文的MDP-MTDSO(Markov decision process based MTD strategies optimization)模型参数如表3所示。在仿真实验中,本文主要考虑基于网络杀伤链的渗透攻击,并采用逻辑时间来代替真实时间,即在每个逻辑时间内,攻击者和防御者都可以完成1个基本动作[22]。同时,每次迭代的结束标志是攻击者达到目标。
CAIG L, WANGB S, WANGT Z, et al. Research and development of moving target defense[J]. Journal of Computer Research and Development, 2016, 53(5):968-987. DOI:10.7544/issn1000-1239.2016.20150225(Ch).
[6]
AL-SHAERE, DUANQ, JAFARIANJ H. Random host mutation for moving target defense [C]// Proceeding of SecureComm 2012: Security and Privacy in Communication Networks. Berlin: Springer, 2012:310-327.
[7]
BADISHIG, HERZBERGA, KEIDARI. Keeping denial-of-service attackers in the dark[J]. IEEE Transactions on Dependable & Secure Computing, 2005, 4(3):191-204.
[8]
ATIGHETCHIM, PAL P, WEBBERF, et al. Adaptive use of network-centric mechanisms in cyber-defense[C]// IEEE International Symposium on Object-Oriented Real⁃Time Distributed Computing. New York: IEEE Press, 2003:183.
[9]
OKHRAVIH, COMELLAA, ROBINSONE, et al. Creating a cyber moving target for critical infrastructure applications [J]. International Journal of Critical Infrastructure Protection, 2012, 5(1):30-39.
[10]
PENGW, LIF, HUANGC T, et al. A moving-target defense strategy for cloud-based services with heterogeneous and dynamic attack surfaces[C]// IEEE International Conference on Communications. New York: IEEE Press, 2014:804-809.
[11]
KC G S, KEROMYTISA D, PREVELAKISV. Countering code-injection attacks with instruction-set randomization[C]//ACM Conference on Computer and Communications Security. New York:ACM, 2003:272-280.
[12]
PAPPASV, POLYCHRONAKISM, KEROMYTISA D. Practical software diversification using in-place code randomization[C]//Moving Target Defense Ⅱ. New York: Springer, 2013:175-202.
[13]
NGUYEN-TUONGA, EVANSD, KNIGHTJ C, et al. Security through redundant data diversity[C]// IEEE International Conference on Dependable Systems and Networks with FTCS and DCC. New York: IEEE Press, 2008:187-196.
[14]
OKHRAVIH, HOBSONT, BIGELOWD, et al. Finding focus in the blur of moving-target techniques[J]. IEEE Security & Privacy, 2013, 12(2):1.
[15]
ABDELRAHMANE, SAADW, NIYATOD. Single controller stochastic games for optimized moving target defense[C]// 2016 IEEE International Conference on Communications. New York: IEEE Press, 2016: 1-6.
[16]
SENGUPTAS, VADLAMUDIS G, KAMBHAMPATIS, et al. A game-theoretic approach to strategy generation for moving target defense in web applications[C]// International Conference on Autonomous Agents and Multiagent Systems (AAMAS). New York:ACM, 2017: 178-186.
[17]
LEIC, MAD H, ZHANGH Q. Optimal strategy selection for moving target defense based on Markov game [J]. IEEE Access, 2017,5(1): 156-169.
[18]
LEIC, ZHANGH Q, WANGL M, et al. Incomplete information Markov game theoretic approach to strategy generation for moving target defense [J]. Computer Communications, 2018, 116(1):184-199.
[19]
TEREFEM B, LEE H, HEO N, et al. Energy-efficient multisite offloading policy using Markov decision process for mobile cloud computing[J]. Pervasive & Mobile Computing, 2016, 27(3):75-89.
XIONGX L, ZHAOG S, XUW G, et al. System attack surface based MTD effectiveness assessment model[J]. Journal of Tsinghua University (Science & Technology), 2019, 59(4):276-283 (Ch).
[22]
HAUSKNECHTM, STONEP. Deep recurrent Q-learning for partially observable MDPS[DB/OL].[2019-09-02].
[23]
XIONGX L, LIK C, ZHAOG S. The evaluation of performance cost for network based moving target defense[J] Journal of Physics Conference Series, 2019:1303(012109).
[24]
XIONGX L, YANGL, ZHAOG S. Effectiveness evaluation model of moving target defense based on system attack surface[J]. IEEE Access, 2019,7(1):9998-10014. DOI: 10.1109/ACCESS.2019.2891613 .