首页> 外文会议>2016 Future Technologies Conference >Mitigating service impersonation attacks in clouds
【24h】

Mitigating service impersonation attacks in clouds

机译:减轻云中的服务模拟攻击

获取原文
获取原文并翻译 | 示例

摘要

Providing security for interacting cloud services requires more than user authentication with passwords or digital certificates and confidentiality in data transmission. Existing data protection mechanisms have previously failed in preventing data theft attacks perpetrated by an insider to the cloud provider or impersonators. In this paper, we focus on the service cloud model, which facilitates the composition and communication among web services owned by different cloud vendors. We augment a detection approach for impersonation attacks with additional analyses to improve the security of communicating web services hosted in the cloud. A statistical model generates a normal behavior profile for individual services and groups of services based on their business tasks. The detection approach monitors the behavior of each service and identifies anomalies as a potential impersonation attack if it deviates significantly from the expected behavior. To verify the impersonation attack, we deploy a cloud-based verification technique, misleading suspicious services with useless responses. The experimental results show that modeling request behavior reliably detects a significant number of impersonation attempts, with a performance degradation that is a reasonable trade-off.
机译:为交互云服务提供安全性需要的不仅仅是使用密码或数字证书的用户身份验证以及数据传输的机密性。现有的数据保护机制先前未能阻止内部人员对云提供商或模仿者实施的数据盗窃攻击。在本文中,我们关注服务云模型,该模型促进了不同云供应商拥有的Web服务之间的组合和通信。我们通过其他分析扩展了模拟攻击的检测方法,以提高在云中托管的Web服务通信的安全性。统计模型会根据其业务任务为单个服务和服务组生成正常的行为配置文件。该检测方法监视每个服务的行为,如果异常与预期行为有很大出入,则将异常识别为潜在的模拟攻击。为了验证模拟攻击,我们部署了基于云的验证技术,误导了具有无用响应的可疑服务。实验结果表明,建模请求行为可以可靠地检测到大量的模拟尝试,并且性能下降是一个合理的权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号