重构网络空间安全防御模型——SARPPR
网络出版日期: 2024-05-18
基金资助
国家重点研发计划(2022YFB31040103);国家自然科学基金(62302507)
版权
SARPPR: reconstructing cyberspace security defense model
Online published: 2024-05-18
Copyright
新型网络安全威胁层出不穷,建立有效的网络安全防御模型已经成为迫切需求和必然趋势。传统的网络安全防御模型包括PDR(Protection-Detection-Response)、PDRR(Protection-Detection-Response-Recovery)和APPDRR(Assessment-Policy Protection-Detection-Reaction-Restoration)模型等,其中经典的APPDRR模型通过风险分析、安全策略、系统防护、动态检测、应急响应和灾难恢复6个环节来提高网络安全性。随着网络攻防手段的不断发展,APPDRR模型已经不能满足网络安全防御的现实需求。随着网络安全态势分析、主动防御、拟态防御、盾立方等新兴网络安全防御技术的提出与发展,亟须对原来的网络空间安全防御模型进行重构和扩充。针对该问题,对APPDRR模型进行了重构,同时根据防护的实际情况,首次提出了“护卫模式+自卫模式+迭代模式”的SARPPR(Sensing-Assessment-Response-Policy-Protection-Restoration)模型,以涵盖和指导网络空间安全防御的最新技术,应对复杂的网络安全威胁。从重要活动安全保障角度出发,在传统“自卫模式”的基础上,本模型提出了“护卫模式”和“迭代模式”,实现了事前预防、事中应对、事后复盘的全生命周期防御。该模型是首个覆盖防御全生命周期的网络空间安全保障模型,可以应对高隐蔽APT(Advanced Persistent Threat)等未知网络安全威胁研判,以及现有信息系统内生安全能力建设等难题。该模型已应用于第24届冬季奥林匹克运动会(简称北京冬奥会)、杭州第19届亚洲运动会(简称杭州亚运会)、第31届世界大学生夏季运动会(简称成都大运会)、中国(深圳)国际文化产业博览交易会(简称文博会)、中国进出口商品交易会(简称广交会)等重大活动的网络安全保障,实现了零事故,实践结果验证了模型的有效性。
方滨兴 , 贾焰 , 李爱平 , 顾钊铨 , 于晗 . 重构网络空间安全防御模型——SARPPR[J]. 网络空间安全科学学报, 2024 , 2(1) : 2 -12 . DOI: 10.20172/j.issn.2097-3136.240101
Faced with the new network security threats, establishing an effective network security defense model has become an urgent need. Traditional network security defense models include PDR (Protection-Detection-Response), PDRR (Protection-Detection-Response-Recovery), and APPDRR (Assessment-Policy Protection-Detection-Reaction-Restoration) models, among which the more classic APPDRR model improves network security through six elements: analysis, policy, protection, detection, response and recovery. With the continuous development of network attack and defense methods, the APPDRR model can no longer satisfy the practical needs of network security defense. With the emergence and development of emerging network security defense technologies such as situation awareness, active defense, mimetic defense and shield cube, there is an urgent need to reconstruct and expand the original cyberspace security defense model. In response to this issue, the APPDRR model was restructured and a SARPPR network security defense model of“guard mode + self-defense mode + iterative mode” was proposed to cover and guide the latest technological development of network security defense and respond to complex network security threats. From the perspective of ensuring the safety of important activities, this model extended the “guard mode” and “iterative mode” on the basis of the traditional “self-defense mode”, and achieved a full lifecycle defense of prevention, response and review analysis. This model was the first cyberspace security assurance model that coverd the entire lifecycle defense, capable of addressing unknown network security threats such as highly covert APT (Advanced Persistent Threat), as well as the challenges of building endogenous security capabilities in existing information system. This model has been applied to the network security guarantee of major events such as the Beijing Winter Olympics Games, 2022 Hangzhou Asian Games, Chengdu Universiade, Cultural Expo and Canton Fair, achieving zero accidents and verifying the effectiveness of this model.
Key words: APPDRR model; SARPPR model; guard mode; self-defense mode; iterative mode
表 1 3种安全模式Table 1 Three security modes |
| 安全概念 | 内涵 | 类比在水中的安全 | 安全人员作用对比 | 安全模式 | 典型方法 |
| 内生安全 | 持枪自卫,用户自保 | 学会游泳,自行渡河 | 游泳教练 | 自卫模式 | 拟态防御,可信计算 |
| 内置安全 | 贴身警卫,随动应对 | 佩戴浮具,安全渡河 | 救生员 | 近卫模式 | 杀毒软件,锁闭保护 |
| 外置安全 | 军警护国,无关用户 | 离开水面,乘船渡河 | 救生船员 | 护卫模式 | 盾立方,安全托管 |
| 1 |
SCHWARTAU W. Time-based security explained: provable security models and formulas for the practitioner and vendor[J]. Computers & Security, 1998, 17 (8): 693- 714.
|
| 2 |
LI D,AUNG Z,WILLIAMS J,et al. P2DR:privacy-preserving demand response system in smart grids[C]//2014 International Conference on Computing,Networking and Communications (ICNC),2014:41-47.
|
| 3 |
ZHANG X,BHUYAN L N. Deficit round-robin scheduling for input-queued switches[J]. IEEE Journal on Selected Areas in Communications,2003,21(4):584-594.
|
| 4 |
DEBNATH B,DAS J C,DE D,et al. Security analysis with novel image masking based quantum-dot cellular automata information security model[J]. IEEE Access,2020,8:117159-117172.
|
| 5 |
JIA Y, FANG B X, LI A P, et al. Artificial intelligence enabled cyberspace security defense[J]. Chinese Journal of Engineering Science, 2021, 23 (3): 98- 105.
|
| 6 |
SATCHIDANANDAN B, KUMAR P R. Dynamic watermarking: active defense of networked cyber–physical systems[J]. Proceedings of the IEEE, 2017, 105 (2): 219- 240.
|
| 7 |
WU J X. Research on cyber mimic defense[J]. Journal of Cyber Security, 2016, 1 (4): 1- 10.
|
| 8 |
GALLOWAY A R,THACKER E. The exploit:a theory of networks[M]. London:University of Minnesota Press,2013.
|
| 9 |
AHMED M S,AL-SHAER E,KHAN L. A novel quantitative approach for measuring network security[C]//IEEE INFOCOM 2008-The 27th Conference on Computer Communications,2008:1957-1965.
|
| 10 |
KALS S,KIRDA E,KRUEGEL C,et al. SecuBat:a web vulnerability scanner[C]//Proceedings of the 15th International Conference on World Wide Web,2006:247-256.
|
| 11 |
DENNING D E. An intrusion-detection model[J]. IEEE Transactions on Software Engineering, 1987, (2): 222- 232.
|
| 12 |
MUKHERJEE B, HEBERLEIN L T, LEVITT K N. Network intrusion detection[J]. IEEE Network, 1994, 8 (3): 26- 41.
|
| 13 |
SHIRAVI H, SHIRAVI A, GHORBANI A A. A survey of visualization systems for network security[J]. IEEE Transactions on Visualization and Computer Graphics, 2011, 18 (8): 1313- 1329.
|
| 14 |
MARIN G A. Network security basics[J]. IEEE Security & Privacy, 2005, 3 (6): 68- 72.
|
| 15 |
IOANNIDIS S,KEROMYTIS A D,BELLOVIN S M,et al. Implementing a distributed firewall[C]//Proceedings of the 7th ACM Conference on Computer and Communications Security,2000:190-199.
|
| 16 |
NELSON T,BARRATT C,DOUGHERTY D J,et al. The margrave tool for firewall analysis[C]//Proceedings of the 24th International Conference on Large Installation System Administration,2010:1-8.
|
| 17 |
GRIMES R A. Malicious mobile code:virus protection for Windows[M]. California:O’ Reilly Media,Inc.,2001.
|
| 18 |
DOSHI B T, DRAVIDA S, HARSHAVARDHANA P, et al. Optical network design and restoration[J]. Bell Labs Technical Journal, 1999, 4 (1): 58- 84.
|
| 19 |
AGHAM V. Unified threat management[J]. International Research Journal of Engineering and Technology, 2016, 3 (4): 32- 36.
|
| 20 |
MILAJERDI S M,GJOMEMO R,ESHETE B,et al. Holmes:real-time APT detection through correlation of suspicious information flows[C]//2019 IEEE Symposium on Security and Privacy (SP),2019:1137-1152.
|
| 21 |
方滨兴, 贾焰, 李爱平, 等. 网络空间靶场技术研究[J]. 信息安全学报, 2016, 1 (3): 1- 9.
FANG B X, JIA Y, LI A P, et al. Cyber Ranges: state-of-the-art and research challenges[J]. Journal of Cyber Security, 2016, 1 (3): 1- 9.
|
| 22 |
MILAJERDI S M,ESHETE B,GJOMEMO R,et al. POIROT:aligning attack behavior with kernel audit records for cyber threat hunting[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security,2019:1795-1812.
|
| 23 |
CHALLENER D,YODER K,CATHERMAN R,et al. A practical guide to trusted computing[M]. London:Pearson Education,2007.
|
| 24 |
PROVOS N. A virtual honeypot framework[C]//Proceedings of the 13th USENIX Conference on Security Symposium,2004.
|
/
| 〈 |
|
〉 |