论文标题

Emulytics的自动发现

Automated Discovery for Emulytics

论文作者

Crussell, Jonathan, Fritz, David, Urias, Vince

论文摘要

Sandia在网络安全研究方面具有广泛的背景,目前正在通过仿真能力扩展其最新建模。但是,Sandia建模方法的一个关键部分是对正在研究的信息系统的发现和规范,以及重新创建具有最高忠诚度以推断有意义结果的规范的能力。 这项工作详细介绍了一种进行信息系统发现和开发工具的方法,以创建高保真仿真模型,该模型可用于评估我们的基础架构信息系统安全姿势以及可能因网络威胁而产生的潜在系统影响。结果是一组工具和技术,可以从网络发现操作系统到模拟复杂系统。 作为一个具体的用途酶,我们在超级计算2016上应用了这些工具和技术,以建模世界上最大的研究网络Scinet。该模型包括我们在仿真平台上启动的五个路由器和近10,000个端点。

Sandia has an extensive background in cybersecurity research and is currently extending its state-of-the-art modeling via emulation capability. However, a key part of Sandia's modeling methodology is the discovery and specification of the information-system under study, and the ability to recreate that specification with the highest fidelity possible in order to extrapolate meaningful results. This work details a method to conduct information system discovery and develop tools to enable the creation of high-fidelity emulation models that can be used to enable assessment of our infrastructure information system security posture and potential system impacts that could result from cyber threats. The outcome are a set of tools and techniques to go from network discovery of operational systems to emulating complex systems. As a concrete usecase, we have applied these tools and techniques at Supercomputing 2016 to model SCinet, the world's largest research network. This model includes five routers and nearly 10,000 endpoints which we have launched in our emulation platform.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源