论文标题
免疫学启发的网络安全体系结构
An Immunology-Inspired Network Security Architecture
论文作者
论文摘要
即将到来的5G网络一直在创建需要新的网络安全体系结构的各种新服务和应用程序。免疫学是对脊椎动物(包括人类)免疫系统的研究,可通过各种防御线保护我们免于感染。通过研究免疫系统和网络安全系统之间的相似之处,我们从免疫学中获得了一些灵感,并提取了一些针对网络安全体系结构设计的准则。我们提出了一种哲学设计原则,该原则正在保持安全性和可用性之间的平衡。然后,我们得出了两个方法论原则:1)通过在异质节点之间的社区合作来实现情境意识和快速反应,以及2)通过在真实的环境中与入侵者持续争夺并积极突变/发展攻击策略来增强防御能力。我们还提出了基于原理设计的参考体系结构。
The coming 5G networks have been enabling the creation of a wide variety of new services and applications which demand a new network security architecture. Immunology is the study of the immune system in vertebrates (including humans) which protects us from infection through various lines of defence. By studying the resemblance between the immune system and network security system, we acquire some inspirations from immunology and distill some guidelines for the design of network security architecture. We present a philosophical design principle, that is maintaining the balance between security and availability. Then, we derive two methodological principles: 1) achieving situation-awareness and fast response through community cooperation among heterogeneous nodes, and 2) Enhancing defense capability through consistently contesting with invaders in a real environment and actively mutating/evolving attack strategies. We also present a reference architecture designed based on the principles.