系统梳理网络欺骗技术的架构与分类,指出现有挑战。
Cyber Deception: State of the art, Trends and Open challenges
- 构建涵盖所有类型方案的通用分类体系
- 对比无AI与含AI的欺骗方案,分析其差异
- 总结当前研究趋势并提出未来关键挑战
网络安全领域对网络欺骗(CYDEC)机制的研究日益增多,反映了应对网络威胁的迫切需求。自诞生以来,CYDEC凭借主动与被动防御能力,在多种实际场景中得到应用。尽管已有大量研究,但文献仍存在显著空白:缺乏对核心组成要素的全面分析、未建立覆盖所有解决方案的通用分类,且缺少在不同应用场景下的综述。本文通过详细回顾构成CYDEC的主要特征,构建了一个全面的分类体系;综述了生成CYDEC的不同框架,提出了更完整的分类;系统研究并比较了现有文献中采用的各类解决方案(包括不使用人工智能和使用人工智能的方案)。最后,讨论了当前研究的主要趋势,并列出未来研究需解决的关键挑战。
原文摘要 · Abstract (English)
The growing interest in cybersecurity has significantly increased articles designing and implementing various Cyber Deception (CYDEC) mechanisms. This trend reflects the urgent need for new strategies to address cyber threats effectively. Since its emergence, CYDEC has established itself as an innovative defense against attackers, thanks to its proactive and reactive capabilities, finding applications in numerous real-life scenarios. Despite the considerable work devoted to CYDEC, the literature still presents significant gaps. In particular, there has not been (i) a comprehensive analysis of the main components characterizing CYDEC, (ii) a generic classification covering all types of solutions, nor (iii) a survey of the current state of the literature in various contexts. This article aims to fill these gaps through a detailed review of the main features that comprise CYDEC, developing a comprehensive classification taxonomy. In addition, the different frameworks used to generate CYDEC are reviewed, presenting a more comprehensive one. Existing solutions in the literature using CYDEC, both without Artificial Intelligence (AI) and with AI, are studied and compared. Finally, the most salient trends of the current state of the art are discussed, offering a list of pending challenges for future research.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。