Multi-Dimensional Moving Target Defense Method Based on Adaptive Simulated Annealing Genetic Algorithm

Author:

Xu Hanyi1,Cheng Guozhen1,Yang Xiaohan1,Liu Wenyan2,Zhou Dacheng2,Guo Wei2

Affiliation:

1. Institute of Information Technology, PLA Information Engineering University, Zhengzhou 450001, China

2. National Digital Switching System Engineering and Technological Research Center, Zhengzhou 450001, China

Abstract

Due to the fine-grained splitting of microservices and frequent communication between microservices, the exposed attack surface of microservices has exploded, facilitating the lateral movement of attackers between microservices. To solve this problem, a multi-dimensional moving target defense method based on an adaptive simulated annealing genetic algorithm (MD2RS) is proposed. Firstly, according to the characteristics of microservices in the cloud, a microservice attack graph is proposed to quantify the attack scenario of microservices in the cloud so as to conveniently and intuitively observe the vulnerability of microservices in the cloud and the dependency relationship between microservices. Secondly, the security gain and resource cost are quantified for the key nodes selected by measuring the degree of dependence of each node according to the degree centrality. Finally, the Adaptive Simulated Annealing Genetic Algorithm (ASAGA) is used to solve the optimal security configuration information of the moving target defense, that is, the combination of the number of copies of the multi-copy deployment and the rotation cycle of the dynamic rotation of microservices, in order to quickly evaluate the security risks of microservices and optimize the security policy. Experiments show that the defense return rate of MD2RS is 85.95% higher than that of the mainstream methods, and the experimental results are conducive to applying this method to the dynamic defense of microservices in the cloud.

Funder

National Key Research and Development Program of China

Major Science and Technology Project of Henan Province in China

Publisher

MDPI AG

Subject

Electrical and Electronic Engineering,Computer Networks and Communications,Hardware and Architecture,Signal Processing,Control and Systems Engineering

Reference34 articles.

1. Cloud-native applications;Gannon;IEEE Cloud Comput.,2017

2. A study on the security implications of information leakages in container clouds;Gao;IEEE Trans. Dependable Secur. Comput.,2018

3. Bardas, A.G., Sundaramurthy, S.C., Ou, X., and DeLoach, S.A. (2017). Computer Security–ESORICS 2017, Proceedings of the 22nd European Symposium on Research in Computer Security, Oslo, Norway, 11–15 September 2017, Springer. Proceedings, Part I 22.

4. Toward proactive, adaptive defense: A survey on moving target defense;Cho;IEEE Commun. Surv. Tutor.,2020

5. Evaluating the effectiveness of shuffle and redundancy mtd techniques in the cloud;Alavizadeh;Comput. Secur.,2021

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3