• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

An active defense technique based
on network security awareness

LIU Shiwen1,5,MA Duoyao2,4,LEI Cheng1,3,5,YIN Shaodong2,4,ZHANG Hongqi1,5   

  1. (1.College of Cryptography Engineering,PLA Information Engineering University,Zhengzhou 450001;
    2.Key Laboratory of Urban ITS Technology Optimization and Integration,Ministry of Public Security PRC,Hefei 230001;
    3.State Key Laboratory of Information Security,Institute of Information Engineering,
    Chinese Academy of Sciences,Beijing 100093;
    4.Anhui Keli Information Industry Co.,Ltd,Hefei 230001;
    5.Henan Key Laboratory of Information Security,Zhengzhou 450001,China)
  • Received:2016-12-27 Revised:2017-02-14 Online:2018-06-25 Published:2018-06-25

Abstract:

As a key technique to break through the bottleneck of passive defense, network active defense becomes a hotspot in network information security. To solve the blindness problem of hopping mechanism in the course of network defense, we propose a novel active defense mechanism based on network security situation awareness. Firstly, a network security situational awareness method based on scanning flow entropy is designed, which enhances the targeted defense by discriminating the adversary scanning strategy. Based on this, an active defense mechanism based on endpoint information transformation is proposed. It can increase the difficulty and the cost of attacks by randomly changing network topology dynamically through transforming endpoint information. Theoretical and experimental analyses show that the proposed active defense technique can be employed efficiently under different scanning strategies.
 

Key words: network security situation awareness, scanning flow entropy, software defined network, active defense, endpoint information transformation