首页> 外文会议>International conference on information security practice and experience >Effective Security Analysis for Combinations of MTD Techniques on Cloud Computing (Short Paper)
【24h】

Effective Security Analysis for Combinations of MTD Techniques on Cloud Computing (Short Paper)

机译:针对云计算中的MTD技术组合的有效安全性分析(论文摘要)

获取原文

摘要

Moving Target Defense (MTD) is an emerging security solution based on continuously changing attack surface thus makes it unpredictable for attackers. Cloud computing could leverage such MTD approaches to prevent its resources and services being compromised from an increasing number of attacks. Most of the existing MTD methods so far have focused on devising subtle strategies for attack surface mitigation, and only a few have evaluated the effectiveness of different MTD techniques deployed in systems. We conducted an in-depth study, based on realistic simulations done on a cloud environment, on the effects of security and reliability for three different MTD techniques: (i) Shuffle, (ii) Redundancy, and (iii) the combination of Shuffle and Redundancy. For comparisons, we use a formal scalable security model to analyse the effectiveness of the MTD techniques. Moreover, we adopt Network Centrality Measures to enhance the performance of security analysis to overcome the exponential computational complexity which is often seen in a large networked mode.
机译:移动目标防御(MTD)是一种基于不断变化的攻击面的新兴安全解决方案,因此使攻击者无法预测。云计算可以利用这种MTD方法来防止其资源和服务受到越来越多的攻击的损害。迄今为止,大多数现有的MTD方法都集中于设计用于缓解攻击面的微妙策略,只有极少数的方法评估了部署在系统中的各种MTD技术的有效性。我们基于在云环境中进行的逼真的模拟,针对三种不同的MTD技术的安全性和可靠性的影响进行了深入研究:(i)随机播放,(ii)冗余和(iii)随机播放和冗余。为了进行比较,我们使用正式的可扩展安全模型来分析MTD技术的有效性。此外,我们采用网络集中性措施来增强安全性分析的性能,以克服大型网络模式中经常出现的指数计算复杂性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号