A Network Stealth Method for Electric Information System Based on Moving Target Defense
摘要
With the increasing frequency of interaction between electric power information system and external systems, it inevitably brings problems such as increased attack surface and vulnerability to external mapping of network key information. Therefore, how to make the network invisible and shield the external network mapping has become a key issue to enhance the security protection capability of the power information system as a key infrastructure. In order to prevent attackers from maliciously detecting and scanning the network, this paper proposes a network stealth method based on moving target defense for power information system of SDP architecture, which constantly changes the address information in the network packets through IP, port address hopping and virtualized gateway hopping to enlarge the detection space of attackers. Specifically, IP and port address hopping changes the addresses displayed in the packets of security terminals and service systems in communication through an adaptive weighted random address selection policy based on the weights of address distances, making it difficult for attackers to obtain the real network configuration. Virtualized gateway hopping, on the basis of IP and port address hopping, constructs multiple virtualized gateways with different configurations within a stealth gateway and executes different hopping policies on different virtualized gateways, and continuously changes the virtualized gateways providing services during communication through a virtualized gateway selection policy based on the consideration of load and hopping overhead, which improves the complexity and unpredictability of address hopping.