信息安全研究 ›› 2023, Vol. 9 ›› Issue (1): 2-.

• 学术论文 •    下一篇

一种基于内生安全的攻击反馈动态调度策略

陈楠楠1姜禹1,2,3胡爱群1,2,4郭丞5
  

  1. 1(东南大学网络空间安全学院南京211189)
    2(紫金山实验室南京211111)
    3(江苏省计算机网络技术重点实验室(东南大学)南京211189)
    4(东南大学移动通信国家重点实验室南京210096)
    5(南京师范大学教育科学学院南京210024)
  • 出版日期:2023-01-01 发布日期:2022-12-30
  • 通讯作者: 陈楠楠 硕士研究生.主要研究方向为物理层安全、内生安全. nnchen@seu.edu.cn
  • 作者简介:陈楠楠 硕士研究生.主要研究方向为物理层安全、内生安全. nnchen@seu.edu.cn 姜禹 博士,副教授.主要研究方向为物理层安全、无线网络安全、物联网技术. jiangyu@seu.edu.cn 胡爱群 博士,教授.主要研究方向为内生安全、物理层安全. aqhu@seu.edu.cn 郭丞 硕士研究生.主要研究方向为现代教育信息化技术、社会网络. guochengxueliang@163.com

An Attack Feedback Dynamic Scheduling Strategy Based on Endogenous Security

  • Online:2023-01-01 Published:2022-12-30

摘要: 为了提高内生安全机制调度策略的高效性和鲁棒性,设计了一种调度时机与调度数量动态调整方法.该方法首先提出一种调度触发器,使用工作时长与异常反馈2种属性共同控制调度进程的切换,并综合考虑系统异构、冗余等因素设计调度工作的整体流程;然后利用历史攻击反馈信息对问题建模,针对不同攻击场景设计更新计算公式,以动态调整调度机制工作时长、执行体数量等属性值;最后设计一个仿真模拟器模拟不同攻击场景,比较各算法运行效果.仿真结果表明,该方法通过自适应调整来协调应对复杂的内外部环境,为DHR结构提供较好的安全性;同时提高执行体利用率,减少冗余资源浪费,以较低的系统开销实现较高的安全增益,性能优于其他单一策略,具有较强的实用性.

关键词: 内生安全, DHR架构, 调度策略, 时机选择, 执行体数量

Abstract: In order to improve the efficiency and robustness of the endogenous security scheduling strategy, a scheduling timing and quantity elastic adjustment method is designed. This method first proposes a scheduling trigger, which uses the two attributes of working time and abnormal feedback to control the switching of scheduling process, and designs the overall flow of scheduling work considering system heterogeneity and redundancy. Then it constructs problem model using historical attack feedback, and designs formulas to dynamically calculate the values for different attack scenarios. Finally, a simulator is designed to simulate different attack scenarios and compare the operation results of each algorithm. Results show that this method can cope with complex internal and external environment through adaptive adjustment, and provide better security for DHR structure. At the same time, it improves the utilization rate of the executor, reduces redundant resource waste, achieves higher security gain with lower system overhead, and outperforms other single strategies, which has strong practicality.

Key words: endogenous security, DHR (dynamic heterogeneous redundancy) structure, scheduling strategy, scheduling timing, number of actuators