With the increasing frequency of interaction between electric power information system and external systems, it inevitably brings problems such as increased attack surface and vulnerability to external mapping of network key information. Therefore, how to make the network invisible and shield the external network mapping has become a key issue to enhance the security protection capability of the power information system as a key infrastructure. In order to prevent attackers from maliciously detecting and scanning the network, this paper proposes a network stealth method based on moving target defense for power information system of SDP architecture, which constantly changes the address information in the network packets through IP, port address hopping and virtualized gateway hopping to enlarge the detection space of attackers. Specifically, IP and port address hopping changes the addresses displayed in the packets of security terminals and service systems in communication through an adaptive weighted random address selection policy based on the weights of address distances, making it difficult for attackers to obtain the real network configuration. Virtualized gateway hopping, on the basis of IP and port address hopping, constructs multiple virtualized gateways with different configurations within a stealth gateway and executes different hopping policies on different virtualized gateways, and continuously changes the virtualized gateways providing services during communication through a virtualized gateway selection policy based on the consideration of load and hopping overhead, which improves the complexity and unpredictability of address hopping.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Network Stealth Method for Electric Information System Based on Moving Target Defense

  • Kai Zhang,
  • Shiying Feng,
  • Wei Cui,
  • Jingzhao Luan,
  • Chao Yang,
  • Sujie Shao

摘要

With the increasing frequency of interaction between electric power information system and external systems, it inevitably brings problems such as increased attack surface and vulnerability to external mapping of network key information. Therefore, how to make the network invisible and shield the external network mapping has become a key issue to enhance the security protection capability of the power information system as a key infrastructure. In order to prevent attackers from maliciously detecting and scanning the network, this paper proposes a network stealth method based on moving target defense for power information system of SDP architecture, which constantly changes the address information in the network packets through IP, port address hopping and virtualized gateway hopping to enlarge the detection space of attackers. Specifically, IP and port address hopping changes the addresses displayed in the packets of security terminals and service systems in communication through an adaptive weighted random address selection policy based on the weights of address distances, making it difficult for attackers to obtain the real network configuration. Virtualized gateway hopping, on the basis of IP and port address hopping, constructs multiple virtualized gateways with different configurations within a stealth gateway and executes different hopping policies on different virtualized gateways, and continuously changes the virtualized gateways providing services during communication through a virtualized gateway selection policy based on the consideration of load and hopping overhead, which improves the complexity and unpredictability of address hopping.