A DTN-based Security Deduction Method Using Attack-Driven Network State Transition

Su Li, Ke Wang, Ru Yan, Xiaojun Zhuang, Yuwei Ma, Haitao Du, Chang Liu · 2024

6G communications network and services will be more complex and dynamic facing higher security risks, so it is important to measure network security risks accurately. In a complex network environment, risk modeling is difficult and inaccurate, while security attack and defense drill is more accurate with long implementation period and high cost, and it is difficult to simulate the attacks of some unknown vulnerabilities. In this paper, a security deduction method based on Digital Twin Network (DTN) is proposed based on the analysis of the state transition of network entities driven by attack events, and fully integrates Digital Twin’s ability to simulate the network state and the ability of the attack and defense platform to perceive security events. The scheme has three advantages: firstly, based on Digital Twin, the existing network state can be truly simulated, and attack scenarios can be randomly set to achieve high degree simulation; Secondly, based on the security attack platform and Digital Twin, the impact of one attack can be completely and accurately fed back, and the attack effect of the twin network can be accurately evaluated by using the security state superposition method based on time series proposed in this paper. Thirdly, the security strategy and capabilities can be dynamically deployed on Digital Twin with fast speed and low cost, which will effectively improve the feasibility of high-degree simulation security deduction. Analysis and experiments show that the method has the advantages of environmental simulation, rapid simulation, accurate deduction and low cost, and has strong application prospects.

Read the paper · More papers on PaperTik