arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.13440cs.CR

移动目标防御中的ε-不可区分性:框架、算法及云案例研究

ε-Indistinguishability In Moving Target Defense: Framework, Algorithms, And Cloud Case Studies

Sailik Sengupta, Ankur Chowdhary

首次发表
浏览论文内容

中文总结 AI 辅助

研究移动目标防御中配置池安全的量化问题,通过形式化将其转化为特定查询,给出四种算法,在云案例研究中测量匿名差距,发现组件延迟差异对匿名性有影响,为MTD设计提供诊断方法。

中文摘要 AI 辅助

移动目标防御(MTD)假定其候选配置池在循环使用时是安全的,即延迟和其他可观测指标不会轻易暴露当前的活动选择,但这一假设在配置池层面尚未得到量化。我们将此配置池安全问题形式化为在每个组件实现选择的笛卡尔积中寻找最大的ε-接近子集,在加性效用模型下将成对不可区分性问题简化为对和集的最密集窗口查询。我们给出了四种跨越不同可扩展性的算法——完全枚举、中间相遇、快速傅里叶变换卷积和蒙特卡罗采样,涵盖了从几十到\(10^{38}\)的配置空间。然后,我们在两个生产云案例研究中对匿名差距进行了端到端测量,发现组件的延迟差异在部署后不会保持不变:一个四路运行时无服务器旋转,在没有其他因素掩盖解释器的情况下,面对与VPC相邻的对手时,匿名性从四路降至三路;而一个包含27种配置的三层堆栈,相同的解释器差异被共享的8毫秒数据库往返吸收,实现了九路有效匿名。该框架和两个案例研究共同为MTD设计提供了一种诊断方法:只有当组件变体之间的延迟差异小到对手无法识别时,旋转组件才会增加匿名性。

英文摘要

Moving Target Defense (MTD) assumes its pool of candidate configurations is safe to cycle among, i.e. latency and other observables do not trivially fingerprint the active choice, but this assumption has not been quantified at the pool level. We formalize this pool-safety problem as finding the largest $\varepsilon$-close subset of the Cartesian product of per-component implementation choices, reducing pairwise indistinguishability under an additive utility model to a densest-window query over a sum-set. We give four algorithms spanning the scalability spectrum -- full enumeration, meet-in-the-middle, FFT convolution, and Monte Carlo sampling -- covering configuration spaces from tens to $10^{38}$. We then measure the anonymity gap end-to-end on two production cloud case studies, and find that a component's latency differences do not survive deployment unchanged: a four-runtime serverless rotation, where nothing else masks the interpreter, collapses from four-way to three-way anonymity against a VPC-adjacent adversary, while a $27$-configuration three-tier stack, where the same interpreter differences are instead absorbed by a shared $8$~ms database round-trip, delivers nine-way effective anonymity. The framework and the two case studies together suggest a diagnostic for MTD design: rotating a component adds anonymity only if the latency differences among its variants are too small for the adversary to identify.

↑