Suppr超能文献

一种基于两层IP跳跃的移动目标防御方法,用于增强移动自组织网络的安全性。

A Two-Layer IP Hopping-Based Moving Target Defense Approach to Enhancing the Security of Mobile Ad-Hoc Networks.

作者信息

Wang Pengkun, Zhou Momiao, Ding Zhizhong

机构信息

School of Computer and Information, Hefei University of Technology, Hefei 230009, China.

Anhui Province Key Laboratory, Industry Safety and Emergency Technology, Hefei University of Technology, Hefei 230009, China.

出版信息

Sensors (Basel). 2021 Mar 28;21(7):2355. doi: 10.3390/s21072355.

Abstract

Mobile ad-hoc networks (MANETs) have great potential applications in military missions or emergency rescue due to their no-infrastructure, self-organizing and multi hop capability characteristics. Obviously, it is important to implement a low-cost and efficient mechanism of anti-invasion, anti-eavesdropping and anti-attack in MANETs, especially for military scenarios. The purpose of intruding or attacking a MANET is usually different from that of wired Internet networks whose security mechanism has been widely explored and implemented. For MANETs, moving target defense (MTD) is a suitable mechanism to enhance the network security, whose basic idea is to continuously and randomly change the system parameters or configuration to create inaccessibility for intruders and attackers. In this paper, a two-layer IP hopping-based MTD approach is proposed, in which device IP addresses or virtual IP addresses change or hop according to the network security status and requirements. The proposed MTD scheme based on the two-layer IP hopping has two major advantages in terms of network security. First, the device IP address of each device is not exposed to the wireless physical channel at all. Second, the two-layer IP hops with individual interval and rules to obtain enhanced security of MANET while maintaining relatively low computational load and communication cost for network control and synchronization. The proposed MTD scheme is implemented in our developed MANET terminals, providing three level of network security: anti-intrusion in normal environment, intrusion detection in offensive environment and anti-eavesdropping in a hostile environment by combining the data encryption technology.

摘要

移动自组织网络(MANETs)由于其无基础设施、自组织和多跳能力的特点,在军事任务或应急救援中具有巨大的潜在应用价值。显然,在MANETs中实现一种低成本且高效的反入侵、反窃听和反攻击机制非常重要,特别是在军事场景中。入侵或攻击MANET的目的通常与有线互联网网络不同,后者的安全机制已得到广泛探索和实施。对于MANETs来说,移动目标防御(MTD)是一种增强网络安全的合适机制,其基本思想是持续随机地更改系统参数或配置,以使入侵者和攻击者无法访问。本文提出了一种基于两层IP跳变的MTD方法,其中设备的IP地址或虚拟IP地址根据网络安全状态和要求进行更改或跳变。所提出的基于两层IP跳变的MTD方案在网络安全方面具有两个主要优点。首先,每个设备的IP地址根本不会暴露在无线物理信道上。其次,两层IP跳变具有各自的间隔和规则,在保持相对较低的网络控制和同步计算负载及通信成本的同时,增强了MANET的安全性。所提出的MTD方案在我们开发的MANET终端中得以实现,通过结合数据加密技术,提供了三个级别的网络安全:正常环境下的反入侵、进攻环境下的入侵检测以及敌对环境下的反窃听。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ab1c/8036356/9ba647506b9c/sensors-21-02355-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验