摘要
组织性复杂、计划性高效和指向性明确的高级持续性威胁(APT)攻击是我国面临的主要威胁之一,APT组织的行动隐匿化、攻击常态化趋势愈加明显。近年来,我国掌握主要的APT活动越来越困难,与APT组织将攻击行为匿迹于正常信息服务和网络活动中,以及将攻击流量藏匿于正常通信流量中不无关系。这种高隐蔽攻击行为隐匿后所处的状态,称之为密态。如何检测发现密态行为并实施体系对抗,是当前网络空间防御要解决的瓶颈性难题之一。文章从澄清网络空间高级攻击活动的流量传输隐匿技术机理角度出发,围绕匿名通信链路构建和流量特征行为检测两个维度,提出流量密态匿迹对抗的研究框架和对抗能力评估指标体系,全面阐述近年来相关研究工作进展、研究方法及解决方案,以期探索网络空间密态对抗能力新的发展方向。
Advanced persistent threat(APT)attacks with complex organization,efficient planning and clear directivity are one of the main threats facing our country,and the trend of covert action and regular attack of APT organizations is becoming more and more obvious.In recent years,it has become more and more difficult for our country to master the main APT activities,which is not unrelated to the fact that APT organizations disappear their attacks into normal information services and network activities,and hide their attack traffic in normal communication traffic.The state in which this kind of highly concealed attack behavior is concealed is called dense state.How to detect dense state behavior and implement system confrontation is one of the bottleneck problems to be solved in the current cyber space defense.From the perspective of clarifying the mechanism of traffic transmission hiding technology for advanced attack activities in cyberspace,this paper puts forward a research framework and countermeasure capability evaluation index system of traffic dense disappearing countermeasure based on two dimensions of anonymous communication link construction and traffic characteristic behavior detection,and comprehensively expounds the relevant research progress,research methods and solutions in recent years.In order to explore the new development direction of dense state countermeasure capability in cyberspace.
作者
王强
刘奕智
李涛
贺小川
WANG Qiang;LIU Yizhi;LI Tao;HE Xiaochuan(Institute of Information Enginering,Chinese Academy of Sciences,Beijing 100093,China;School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100049,China;School of Cyber Science and Engineering,Southeast University,Nanjing 210000,China;Purple Mountain Laboratories,Nanjing 210000,China;Qi’anxin Technology Group Co.,Ltd.,Beijing 100044,China;China Electronics Corporation CyberSecurity Research Institute,Beijing 100088,China)
出处
《信息网络安全》
CSCD
北大核心
2024年第10期1484-1492,共9页
Netinfo Security
基金
国家重点研发计划[2021YFB3101400]。
关键词
密态匿迹
流量混淆
体系对抗
encrypted anonymity
network traffic obfuscation
systemic defense tactics