首页|网络流量密态匿迹与体系对抗综述

网络流量密态匿迹与体系对抗综述

Review of Encrypted Network Traffic Anonymity and Systemic Defense Tactics

扫码查看
组织性复杂、计划性高效和指向性明确的高级持续性威胁(APT)攻击是我国面临的主要威胁之一,APT组织的行动隐匿化、攻击常态化趋势愈加明显.近年来,我国掌握主要的APT活动越来越困难,与APT组织将攻击行为匿迹于正常信息服务和网络活动中,以及将攻击流量藏匿于正常通信流量中不无关系.这种高隐蔽攻击行为隐匿后所处的状态,称之为密态.如何检测发现密态行为并实施体系对抗,是当前网络空间防御要解决的瓶颈性难题之一.文章从澄清网络空间高级攻击活动的流量传输隐匿技术机理角度出发,围绕匿名通信链路构建和流量特征行为检测两个维度,提出流量密态匿迹对抗的研究框架和对抗能力评估指标体系,全面阐述近年来相关研究工作进展、研究方法及解决方案,以期探索网络空间密态对抗能力新的发展方向.
Advanced persistent threat(APT)attacks with complex organization,efficient planning and clear directivity are one of the main threats facing our country,and the trend of covert action and regular attack of APT organizations is becoming more and more obvious.In recent years,it has become more and more difficult for our country to master the main APT activities,which is not unrelated to the fact that APT organizations disappear their attacks into normal information services and network activities,and hide their attack traffic in normal communication traffic.The state in which this kind of highly concealed attack behavior is concealed is called dense state.How to detect dense state behavior and implement system confrontation is one of the bottleneck problems to be solved in the current cyber space defense.From the perspective of clarifying the mechanism of traffic transmission hiding technology for advanced attack activities in cyberspace,this paper puts forward a research framework and countermeasure capability evaluation index system of traffic dense disappearing countermeasure based on two dimensions of anonymous communication link construction and traffic characteristic behavior detection,and comprehensively expounds the relevant research progress,research methods and solutions in recent years.In order to explore the new development direction of dense state countermeasure capability in cyberspace.

encrypted anonymitynetwork traffic obfuscationsystemic defense tactics

王强、刘奕智、李涛、贺小川

展开 >

中国科学院信息工程研究所,北京 100093

中国科学院大学网络空间安全学院,北京 100049

东南大学网络空间安全学院,南京 210000

网络通信与安全紫金山实验室,南京 210000

奇安信科技集团股份有限公司,北京 100044

中国电子网络空间安全研究院,北京 100088

展开 >

密态匿迹 流量混淆 体系对抗

国家重点研发计划

2021YFB3101400

2024

信息网络安全
公安部第三研究所 中国计算机学会计算机安全专业委员会

信息网络安全

CSTPCDCHSSCD北大核心
影响因子:0.814
ISSN:1671-1122
年,卷(期):2024.24(10)