【24h】

SubDomain: Parsimonious Server Security

机译:子域:简约服务器安全性

获取原文
获取原文并翻译 | 示例

摘要

Internet security incidents have shown that while network cryptography tools like SSL are valuable to Internet service, the hard problem is to protect the server itself from attack. The host security problem is important because attackers know to attack the weakest link, which is vulnerable servers. The problem is hard because securing a server requires securing every piece of software on the server that the attacker can access, which can be a very large set of software for a sophisticated server. Sophisticated security architectures that protect against this class of problem exist, but because they are either complex, expensive, or incompatible with existing application software, most Internet server operators have not chosen to use them. This paper presents SubDomain: an OS extension designed to provide sufficient security to prevent vulnerability rot in Internet server platforms, and yet simple enough to minimize the performance, administrative, and implementation costs. SubDomain does this by providing a least privilege mechanism for programs rather than for users. By orienting itself to programs rather than users, SubDomain simplifies the security administrator's task of securing the server. This paper describes the problem space of securing Internet servers, and presents the SubDomain solution to this problem. We describe the design, implementation, and operation of SubDomain, and provide working examples and performance metrics for services such as HTTP, SMTP, POP, and DNS protected with SubDomain.
机译:互联网安全事件表明,尽管像SSL这样的网络加密工具对互联网服务很有价值,但最棘手的问题是保护服务器本身不受攻击。主机安全问题很重要,因为攻击者知道攻击最脆弱的链接,这是易受攻击的服务器。这个问题很难解决,因为保护服务器安全需要保护攻击者可以访问的服务器上的所有软件,对于复杂服务器而言,这可能是非常庞大的一组软件。虽然存在防止此类问题的复杂安全性体系结构,但是由于它们既复杂,昂贵又与现有应用程序软件不兼容,因此大多数Internet服务器运营商并未选择使用它们。本文介绍了SubDomain:这是一个OS扩展,旨在提供足够的安全性以防止Internet服务器平台上的漏洞腐烂,但又足够简单以最小化性能,管理和实现成本。 SubDomain通过为程序而非用户提供最小特权机制来做到这一点。通过将自己定位于程序而非用户,SubDomain简化了安全管理员保护服务器安全的任务。本文介绍了保护Internet服务器安全的问题空间,并提出了解决该问题的SubDomain解决方案。我们描述了SubDomain的设计,实现和操作,并提供了受SubDomain保护的服务(例如HTTP,SMTP,POP和DNS)的工作示例和性能指标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号