首页> 外文会议>International Symposium on Resilient Control Systems >A case for validating remote application integrity for data processing systems
【24h】

A case for validating remote application integrity for data processing systems

机译:用于验证数据处理系统的远程应用程序完整性的案例

获取原文

摘要

There has been a great increase in recent years as to the amount of data from the grid that has been going to online systems. As more smart meters get installed into the AMI(advanced metering infrastructure), there is a need to mitigate the potential security threats in the collection system. There are a multitude of attack vectors that an adversary may take to compromise the confidentiality of user data and it may take much time and effort for developers to securely cover all such attack vectors. In this paper, we analyze the architecture of AMI systems and how data moves from one end to the other. In particular, we discuss the need for more research in safe program validation that protects against information leaks. Security problems can arise when programs do not perform as intended and may reveal confidential information or take unexpected actions. We discuss a theoretical network architecture that could take advantage of such secure program validation. The model minimizes attack vectors by containing data in one secure location that we call a DBPC(database processing center) instead of transporting data to multiple locations through a traditional DBMS(database management system). When outside parties want access to the data, they can send verified secure applications to the DBPC to run their applications remotely without direct access to the data. We describe the design of the AMI simulator and DBPC prototype module that we implemented.
机译:近年来迄今为止已经参加在线系统的网格数量的数据繁重。随着更智能电表安装到AMI(高级计量基础架构)中,需要减轻收集系统中的潜在安全威胁。存在众多攻击向量,对手可能需要损害用户数据的机密性,并且开发人员可以牢固地覆盖所有这样的攻击向量可能需要很多时间和精力。在本文中,我们分析了AMI系统的架构以及数据如何从一端移动到另一端。特别是,我们讨论了在安全的程序验证中进行更多研究,以防止信息泄漏。当程序不按预期执行时可能会出现安全问题,并且可以揭示机密信息或采取意外行动。我们讨论了一个理论网络架构,可以利用这种安全的程序验证。该模型通过在一个安全位置中包含数据来最小化攻击向量,我们通过传统的DBMS(数据库管理系统)呼叫DBPC(数据库处理中心)而不是将数据传输到多个位置。当外部派对希望访问数据时,他们可以将验证的安全应用程序发送到DBPC以远程运行应用程序,而不直接访问数据。我们描述了我们实施的AMI模拟器和DBPC原型模块的设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号