Shock Trap: an Active Defense Architecture Based on Trap Vulnerabilities

Quan Hong,Yang Zhao,Jian Chang,Yuxin Du,Jun Li,Lidong Zhai
DOI: https://doi.org/10.1109/dsc55868.2022.00011
2022-01-01
Abstract:Unlike traditional defense concepts, active defense is an asymmetric defense concept. It can not only identify potential threats in advance and nip them in the bud but also increase the attack cost of unknown threats by using change, interference, deception, or other means. Although active defense can reverse the asymmetric situation between attacks and defenses, current active defense technologies have two shortcomings: (i) they mainly aim at detecting attacks and increasing the cost of attacks without addressing the underlying problem; and (ii) they have problems such as high deployment costs and compromised system operational efficiency. This paper proposes an active defense architecture based on trap vulnerability with vulnerability as the core and introduces its design concept and specific implementation scheme. We deploy “traps” in the system to lure and find attackers while combining built-in detection, rejection, and traceback mechanisms to protect the system and trace the source of the attack.
What problem does this paper attempt to address?