Abstract
Mimic active defense technology effectively disrupts attack routes and reduces the probability of successful attacks by using a dynamic heterogeneous redundancy (DHR) architecture. However, current approaches often overlook the adaptability of the adjudication mechanism in complex and variable network environments, focusing primarily on system security while neglecting performance considerations. To address these limitations, we propose an output difference feedback and system benefit control based DHR architecture. This architecture introduces an adjudication mechanism based on output difference feedback, which enhances adaptability by considering the impact of each executor’s output deviation on the global decision. Additionally, the architecture incorporates a scheduling strategy based on system benefit, which models the quality of service and switching overhead as a bi-objective optimization problem, balancing security with reduced computational costs and system overhead. Simulation results demonstrate that our architecture improves adaptability towards different network environments and effectively reduces both the attack success rate and average failure rate.
摘要
拟态主动防御技术通过引入动态异构冗余架构来有效扰乱攻击路线, 降低攻击成功率。 然而, 现有方法忽略裁决机制在复杂可变网络环境中的适应性, 往往聚焦系统安全性而忽视系统性能。 为解决前述局限, 本文提出一种基于输出差异反馈和系统效益控制的动态异构冗余架构。 该架构引入一种基于输出差异反馈的裁决机制, 通过量化各执行体输出偏差对全局裁决结果的影响来增强适应性。 此外, 该架构结合一种基于系统效益的调度策略, 将服务质量和切换开销建模为双目标优化问题, 在降低计算成本和系统开销的同时平衡系统安全。 仿真结果表明, 该架构增强了对不同网络环境的适应能力, 有效降低了攻击成功率和平均裁决失败率。
Similar content being viewed by others
Data availability
The data that support the findings of this study are available from the corresponding author upon reasonable request.
References
Cho JH, Sharma DP, Alavizadeh H, et al., 2020. Toward proactive, adaptive defense: a survey on moving target defense. IEEE Commun Surv Tut, 22(1):709–745. https://doi.org/10.1109/COMST.2019.2963791
Fu T, Zhen W, Yang F, et al., 2022. Mimic defense equivalent scheduling algorithm based on service quality and credit. IEEE 6th Information Technology and Mechatronics Engineering Conf, p.414–419. https://doi.org/10.1109/ITOEC53115.2022.9734532
Hu HC, Wu JX, Wang ZP, et al., 2018. Mimic defense: a designed-in cybersecurity defense framework. IET Inform Secur, 12(3):226–237. https://doi.org/10.1049/iet-ifs.2017.0086
Hu JJ, Li Y, Li ZZ, et al., 2024. Unveiling the strategic defense mechanisms in dynamic heterogeneous redundancy architecture. IEEE Trans Netw Serv Manag, 21(4):4912–4926. https://doi.org/10.1109/TNSM.2024.3387725
Jiang DD, Wang ZH, Huo LW, et al., 2021. A performance measurement and analysis method for software-defined networking of IoV. IEEE Trans Intell Transp Syst, 22(6):3707–3719. https://doi.org/10.1109/TITS.2020.3029076
Jiang DD, Wang F, Lv ZH, et al., 2023. QoE-aware efficient content distribution scheme for satellite-terrestrial networks. IEEE Trans Mob Comput, 22(1):443–458. https://doi.org/10.1109/TMC.2021.3074917
Jiang DD, Wang ZH, Wang Y, et al., 2024. A blockchain-reinforced federated intrusion detection architecture for IIoT. IEEE Int Things J, 11(16):26793–26805. https://doi.org/10.1109/JIOT.2024.3406602
Li GS, Wang W, Gai KK, et al., 2021. A framework for mimic defense system in cyberspace. J Signal Process Syst, 93(2):169–185. https://doi.org/10.1007/s11265-019-01473-6
Lin SJ, Liu QR, Wang XL, 2018. Competitive arbitration model for mimic defense system. Comput Eng, 44(4):193–198 (in Chinese). https://doi.org/10.3969/j.issn.1000-3428.2018.04.031
Lin X, Wu J, Li JH, et al., 2023. Heterogeneous differentialprivate federated learning: trading privacy for utility truthfully. IEEE Trans Depend Secur Comput, 20(6):5113–5129. https://doi.org/10.1109/TDSC.2023.3241057
Liu QR, Lin SJ, Gu ZY, 2018. Heterogeneous redundancies scheduling algorithm for mimic security defense. J Commun, 39(7):188–198 (in Chinese). https://doi.org/10.11959/j.issn.1000-436x.2018124
Lu YQ, Huang JX, Cheng Z, et al., 2021. A multi-index mimic voting algorithm based on improved AHP-FCE model. J Beijing Univ Posts Telecommun, 44(2):8–13 (in Chinese). https://doi.org/10.13190/j.jbupt.2020-105
Lu ZP, Chen FC, Cheng GZ, et al., 2017. Towards a dynamic controller scheduling-timing problem in software-defined networking. China Commun, 14(10):26–38. https://doi.org/10.1109/CC.2017.8107630
Lucy W, 2024. Algorithms and adjudication. Jurisprudence, 15(3):251–281. https://doi.org/10.1080/20403313.2023.2243712
Rehman Z, Gondal I, Ge MM, et al., 2024. Proactive defense mechanism: enhancing IoT security through diversity-based moving target defense and cyber deception. Comput Secur, 139:103685. https://doi.org/10.1016/j.cose.2023.103685
Ren Q, Wu JX, He L, 2020. Performance modeling based on GSPN for cyberspace mimic DNS. Chin J Electron, 29(4):738–749. https://doi.org/10.1049/cje.2020.05.001
Shao SS, Ji YM, Zhang WL, et al., 2023a. A DHR executor selection algorithm based on historical credibility and dissimilarity clustering. Sci China Inform Sci, 66(11):212304. https://doi.org/10.1007/s11432-022-3635-2
Shao SS, Liu SD, Li K, et al., 2023b. LBA-EC: load balancing algorithm based on weighted bipartite graph for edge computing. Chin J Electron, 32(2):313–324. https://doi.org/10.23919/cje.2021.00.289
Tong Q, Guo YF, 2021. A comprehensive evaluation of diversity systems based on mimic defense. Sci China Inform Sci, 64(12):229304. https://doi.org/10.1007/s11432-020-3008-1
Wang YW, Wu JX, Guo YF, et al., 2018. Scientific workflow execution system based on mimic defense in the cloud environment. Front Inform Technol Electron Eng, 19(12):1522–1536. https://doi.org/10.1631/FITEE.1800621
Wang ZH, Jiang DD, Wang F, et al., 2021. A polymorphic heterogeneous security architecture for edge-enabled smart grids. Sustain Cities Soc, 67:102661. https://doi.org/10.1016/j.scs.2020.102661
Wang ZH, Jiang DD, Lv ZH, 2023. AI-assisted trustworthy architecture for industrial IoT based on dynamic heterogeneous redundancy. IEEE Trans Ind Inform, 19(2):2019–2027. https://doi.org/10.1109/TII.2022.3210139
Wei D, Xiao L, Shi L, et al., 2022. Mimic web application security technology based on DHR architecture. Proc Int Conf on Artificial Intelligence and Intelligent Information Processing, p.118–124. https://doi.org/10.1117/12.2660317
Wu JX, 2022a. Cyberspace endogenous safety and security. Engineering, 15:179–185. https://doi.org/10.1016/j.eng.2021.05.015
Wu JX, 2022b. Development paradigms of cyberspace endogenous safety and security. Sci China Inform Sci, 65(5):156301. https://doi.org/10.1007/s11432-021-3379-2
Wu T, Hu CN, Chen QN, et al., 2021. Defense-enhanced dynamic heterogeneous redundancy architecture based on executor partition. J Commun, 42(3):122–134 (in Chinese). https://doi.org/10.11959/j.issn.1000-436x.2021022
Yadav D, Raj BAA, 2024. An efficient swarm intelligence algorithm for multi-objective task scheduling optimization in the context of cloud computing. Int Conf on Automation and Computation, p.148–152. https://doi.org/10.1109/AUTOCOM60220.2024.10486073
Yu F, Liu K, Geng YY, et al., 2022. Multi executor decision algorithm and scheduling algorithm based on differential distance feedback. Appl Res Comput, 39(5):1437–1443 (in Chinese). https://doi.org/10.19734/j.issn.1001-3695.2021.10.0462
Zhang JX, Pang JM, Zhang Z, 2020. Quantification method for heterogeneity on web server with mimic construction. J Softw, 31(2):564–577 (in Chinese). https://doi.org/10.13328/j.cnki.jos.005615
Zheng Y, Li Z, Xu XL, et al., 2022. Dynamic defenses in cyber security: techniques, methods and challenges. Digit Commun Netw, 8(4):422–435. https://doi.org/10.1016/j.dcan.2021.07.006
Zhu ZB, Liu QR, Liu DP, et al., 2021. Research progress of mimic multi-execution scheduling algorithm. J Commun, 42(5):179–190 (in Chinese). https://doi.org/10.11959/j.issn.1000-436x.2021072
Author information
Authors and Affiliations
Contributions
Sisi SHAO designed the research. Zhibo HE, Fukang ZENG, Jun ZUO, and Longfei ZHOU processed the data. Sisi SHAO drafted the paper. Weili ZHANG, Fei WU, and Yukun NIU helped organize the paper. Shangdong LIU and Yimu JI revised and finalized the paper.
Corresponding author
Ethics declarations
All the authors declare that they have no conflict of interest.
Additional information
Project supported by the National Key R&D Program of China (Nos. 2023YFB2904004 and 2023YFB2904000), the Jiangsu Key Development Planning Project (No. BE2023004-2), the Natural Science Foundation of Jiangsu Province (Higher Education Institutions) (No. 20KJA520001), and the Postgraduate Research Practice Innovation Program of Jiangsu Province (No. KYCX22_1021)
Rights and permissions
About this article
Cite this article
Shao, S., He, Z., Liu, S. et al. Output difference feedback and system benefit control based dynamic heterogeneous redundancy architecture. Front Inform Technol Electron Eng 26, 1279–1292 (2025). https://doi.org/10.1631/FITEE.2400251
Received:
Accepted:
Published:
Version of record:
Issue date:
DOI: https://doi.org/10.1631/FITEE.2400251
