Rlaph: a lightweight and dynamic proactive defense method in cloud-edge collaboration
摘要
In cloud-edge collaboration scenarios, attackers pose significant security risks by compromising computational nodes and using them to infiltrate other nodes and networks. Ensuring the security of cloud-edge collaboration is crucial for protecting sensitive data, preventing disruptions to critical services, and safeguarding infrastructure in increasingly interconnected and digitized societies. Traditional passive defense mechanisms are often inadequate in dealing with the complex and dynamic nature of modern network threats. In recent years, Moving Target Defense (MTD) has become an important research direction, disrupting adversaries’ reconnaissance and exploitation phases by dynamically shuffling the attack surface. However, existing MTD strategies have some shortcomings, such as single-dimensional movement strategies, poor flexibility and a lack of historical information analysis. To overcome these challenges, we propose a reinforcement learning-based approach for host address and port hopping (RLAPH). First, the approach strengthens system security through coordinated decision-making across IP address and port, leveraging both historical data and current information to make accurate and adaptive decisions. Second, a reward function is carefully designed to balance the trade-off between system overhead and security. Finally, validation experiments conducted in a simulated environment show that the proposed method effectively enhances defense performance while minimizing system overhead, highlighting its robustness and applicability.