SARPPR: reconstructing cyberspace security defense model
Online published: 2024-05-18
Copyright
Faced with the new network security threats, establishing an effective network security defense model has become an urgent need. Traditional network security defense models include PDR (Protection-Detection-Response), PDRR (Protection-Detection-Response-Recovery), and APPDRR (Assessment-Policy Protection-Detection-Reaction-Restoration) models, among which the more classic APPDRR model improves network security through six elements: analysis, policy, protection, detection, response and recovery. With the continuous development of network attack and defense methods, the APPDRR model can no longer satisfy the practical needs of network security defense. With the emergence and development of emerging network security defense technologies such as situation awareness, active defense, mimetic defense and shield cube, there is an urgent need to reconstruct and expand the original cyberspace security defense model. In response to this issue, the APPDRR model was restructured and a SARPPR network security defense model of“guard mode + self-defense mode + iterative mode” was proposed to cover and guide the latest technological development of network security defense and respond to complex network security threats. From the perspective of ensuring the safety of important activities, this model extended the “guard mode” and “iterative mode” on the basis of the traditional “self-defense mode”, and achieved a full lifecycle defense of prevention, response and review analysis. This model was the first cyberspace security assurance model that coverd the entire lifecycle defense, capable of addressing unknown network security threats such as highly covert APT (Advanced Persistent Threat), as well as the challenges of building endogenous security capabilities in existing information system. This model has been applied to the network security guarantee of major events such as the Beijing Winter Olympics Games, 2022 Hangzhou Asian Games, Chengdu Universiade, Cultural Expo and Canton Fair, achieving zero accidents and verifying the effectiveness of this model.
Key words: APPDRR model; SARPPR model; guard mode; self-defense mode; iterative mode
FANG Binxing , JIA Yan , LI Aiping , GU Zhaoquan , YU Han . SARPPR: reconstructing cyberspace security defense model[J]. Journal of Cybersecurity, 2024 , 2(1) : 2 -12 . DOI: 10.20172/j.issn.2097-3136.240101
表 1 3种安全模式Table 1 Three security modes |
| 安全概念 | 内涵 | 类比在水中的安全 | 安全人员作用对比 | 安全模式 | 典型方法 |
| 内生安全 | 持枪自卫,用户自保 | 学会游泳,自行渡河 | 游泳教练 | 自卫模式 | 拟态防御,可信计算 |
| 内置安全 | 贴身警卫,随动应对 | 佩戴浮具,安全渡河 | 救生员 | 近卫模式 | 杀毒软件,锁闭保护 |
| 外置安全 | 军警护国,无关用户 | 离开水面,乘船渡河 | 救生船员 | 护卫模式 | 盾立方,安全托管 |
| 1 |
SCHWARTAU W. Time-based security explained: provable security models and formulas for the practitioner and vendor[J]. Computers & Security, 1998, 17 (8): 693- 714.
|
| 2 |
LI D,AUNG Z,WILLIAMS J,et al. P2DR:privacy-preserving demand response system in smart grids[C]//2014 International Conference on Computing,Networking and Communications (ICNC),2014:41-47.
|
| 3 |
ZHANG X,BHUYAN L N. Deficit round-robin scheduling for input-queued switches[J]. IEEE Journal on Selected Areas in Communications,2003,21(4):584-594.
|
| 4 |
DEBNATH B,DAS J C,DE D,et al. Security analysis with novel image masking based quantum-dot cellular automata information security model[J]. IEEE Access,2020,8:117159-117172.
|
| 5 |
JIA Y, FANG B X, LI A P, et al. Artificial intelligence enabled cyberspace security defense[J]. Chinese Journal of Engineering Science, 2021, 23 (3): 98- 105.
|
| 6 |
SATCHIDANANDAN B, KUMAR P R. Dynamic watermarking: active defense of networked cyber–physical systems[J]. Proceedings of the IEEE, 2017, 105 (2): 219- 240.
|
| 7 |
WU J X. Research on cyber mimic defense[J]. Journal of Cyber Security, 2016, 1 (4): 1- 10.
|
| 8 |
GALLOWAY A R,THACKER E. The exploit:a theory of networks[M]. London:University of Minnesota Press,2013.
|
| 9 |
AHMED M S,AL-SHAER E,KHAN L. A novel quantitative approach for measuring network security[C]//IEEE INFOCOM 2008-The 27th Conference on Computer Communications,2008:1957-1965.
|
| 10 |
KALS S,KIRDA E,KRUEGEL C,et al. SecuBat:a web vulnerability scanner[C]//Proceedings of the 15th International Conference on World Wide Web,2006:247-256.
|
| 11 |
DENNING D E. An intrusion-detection model[J]. IEEE Transactions on Software Engineering, 1987, (2): 222- 232.
|
| 12 |
MUKHERJEE B, HEBERLEIN L T, LEVITT K N. Network intrusion detection[J]. IEEE Network, 1994, 8 (3): 26- 41.
|
| 13 |
SHIRAVI H, SHIRAVI A, GHORBANI A A. A survey of visualization systems for network security[J]. IEEE Transactions on Visualization and Computer Graphics, 2011, 18 (8): 1313- 1329.
|
| 14 |
MARIN G A. Network security basics[J]. IEEE Security & Privacy, 2005, 3 (6): 68- 72.
|
| 15 |
IOANNIDIS S,KEROMYTIS A D,BELLOVIN S M,et al. Implementing a distributed firewall[C]//Proceedings of the 7th ACM Conference on Computer and Communications Security,2000:190-199.
|
| 16 |
NELSON T,BARRATT C,DOUGHERTY D J,et al. The margrave tool for firewall analysis[C]//Proceedings of the 24th International Conference on Large Installation System Administration,2010:1-8.
|
| 17 |
GRIMES R A. Malicious mobile code:virus protection for Windows[M]. California:O’ Reilly Media,Inc.,2001.
|
| 18 |
DOSHI B T, DRAVIDA S, HARSHAVARDHANA P, et al. Optical network design and restoration[J]. Bell Labs Technical Journal, 1999, 4 (1): 58- 84.
|
| 19 |
AGHAM V. Unified threat management[J]. International Research Journal of Engineering and Technology, 2016, 3 (4): 32- 36.
|
| 20 |
MILAJERDI S M,GJOMEMO R,ESHETE B,et al. Holmes:real-time APT detection through correlation of suspicious information flows[C]//2019 IEEE Symposium on Security and Privacy (SP),2019:1137-1152.
|
| 21 |
方滨兴, 贾焰, 李爱平, 等. 网络空间靶场技术研究[J]. 信息安全学报, 2016, 1 (3): 1- 9.
FANG B X, JIA Y, LI A P, et al. Cyber Ranges: state-of-the-art and research challenges[J]. Journal of Cyber Security, 2016, 1 (3): 1- 9.
|
| 22 |
MILAJERDI S M,ESHETE B,GJOMEMO R,et al. POIROT:aligning attack behavior with kernel audit records for cyber threat hunting[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security,2019:1795-1812.
|
| 23 |
CHALLENER D,YODER K,CATHERMAN R,et al. A practical guide to trusted computing[M]. London:Pearson Education,2007.
|
| 24 |
PROVOS N. A virtual honeypot framework[C]//Proceedings of the 13th USENIX Conference on Security Symposium,2004.
|
/
| 〈 |
|
〉 |