拟态防御技术结合软件多样化在软件安全产业中的应用
Applying a Combination of Mimic Defense and Software Diversity in the Software Security Industry
随着互联网的飞速发展,计算机软件全球化的进程不断推进。大量相同软件安装在数以万计的计算机中,容易导致黑客利用软件的漏洞,攻击安装了该软件的所有计算机。传统的软件安全措施是依靠对漏洞进行修补,其只能起到亡羊补牢的作用。软件多样化技术可以使这种情况得到缓解,但其并没有从根本上消除漏洞带来的威胁。本文提出将拟态防御技术与软件多样化技术相结合应用于软件安全产业,可以消除漏洞带来的威胁。
With the development of the Internet, the process of computer software globalization continues to push forward. For widely used software, anidentical binary code is installed on millions of computers; sometimes even hundreds of millions. This makes widespread exploitation easy and attractive for an attacker because the same attack vector is likely to succeed on a large number of targets. Traditional software security methods can only counter the threat temporarily, and cannot eliminate essential vulnerabilities. This paper proposes a scheme of combining software diversity with mimic defense in the software security industry.
软件多样化 / 拟态防御 / 软件安全产业 / software diversity / mimic defense / software security product
| [1] |
中国互联网络信息中心. 第38次中国互联网络发展状况统计报告 [EB/OL]. (2016-08-03)[2016-10-08]. http://www.cnnic.net.cn/hlwfzyj/hlwxzbg/hlwtjbg/201608/t20160803_54392.htm. |
| [2] |
Symantec Corporation. Internet security threat report 2016 [R/OL]. (2016-04-01) [2016-10-08]. |
| [3] |
倪光南. 信息安全“本质”是自主可控[J]. 中国经济和信息化, 2013(5):18–19. |
| [4] |
Cohen F B. Operating system protection through program evolu-分发器A B表决器用户输入程序输出C图 2 基于拟态防御的设计框架078专题研究 拟态防御技术结合软件多样化在软件安全产业中的应用tion [J]. Computers & Security, 1993, 12(6): 565–584. |
| [5] |
邬江兴. 专题导读——拟态计算与拟态安全防御的原意和愿景[J]. 电信科学, 2014, 30(7): 1–7. |
| [6] |
Jackson T, Salamat B, Homescu A, et al. Compiler-generated soft-ware diversity[M]//Jajodia S, Ghosh A K, Swarup V, et al. Moving Target Defense. New York: Springer, 2011: 77–98. |
| [7] |
邬江兴. 网络空间拟态安全防御[J]. 保密科学技术, 2014, 10(1): 4–9. |
中国工程院重大咨询项目“网络空间安全战略研究”(2015-ZD-10)()
/
| 〈 |
|
〉 |