论文标题
计算机和网络安全的网络欺骗:调查和挑战
Cyber Deception for Computer and Network Security: Survey and Challenges
论文作者
论文摘要
网络欺骗最近已获得越来越多的注意力,这是积极的网络防御机制。网络欺骗策略旨在注入故意伪造的信息,以破坏攻击侦察的早期阶段和计划,以使最终的攻击行动无害或无效。在网络欺骗研究的最新进展中,我们在本文中提供了对网络欺骗的正式观点,并回顾了高级欺骗计划和行动。我们还总结并分类了基于网络欺骗概念的网络防御技术的最新研究结果,包括在战略层面上进行游戏理论建模,网络级别的欺骗,托管系统内部欺骗和基于密码学的欺骗。最后,我们布置并详细讨论了开发成熟的网络欺骗框架和机制的研究挑战。
Cyber deception has recently received increasing attentions as a promising mechanism for proactive cyber defense. Cyber deception strategies aim at injecting intentionally falsified information to sabotage the early stage of attack reconnaissance and planning in order to render the final attack action harmless or ineffective. Motivated by recent advances in cyber deception research, we in this paper provide a formal view of cyber deception, and review high-level deception schemes and actions. We also summarize and classify recent research results of cyber defense techniques built upon the concept of cyber deception, including game-theoretic modeling at the strategic level, network-level deception, in-host-system deception and cryptography based deception. Finally, we lay out and discuss in detail the research challenges towards developing full-fledged cyber deception frameworks and mechanisms.