首页> 外文会议>European symposium on research in computer security >MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
【24h】

MTD CBITS: Moving Target Defense for Cloud-Based IT Systems

机译:MTD CBITS:基于云的IT系统的移动目标防御

获取原文

摘要

The static nature of current IT systems gives attackers the extremely valuable advantage of time, as adversaries can take their time and plan attacks at their leisure. Although cloud infrastructures have increased the automation options for managing IT systems, the introduction of Moving Target Defense (MTD) techniques at the entire IT system level is still very challenging. The core idea of MTD is to make a system change proactively as a means to eliminating the asymmetric advantage the attacker has on time. However, due to the number and complexity of dependencies between IT system components, it is not trivial to introduce proactive changes without breaking the system or severely impacting its performance. In this paper, we present an MTD platform for Cloud-Based IT Systems (MTD CBITS), evaluate its practicality, and perform a detailed analysis of its security benefits. To the best of our knowledge MTD CBITS is the first MTD platform that leverages the advantages of a cloud-automation framework (ANCOR) that captures an IT system's setup parameters and dependencies using a high-level abstraction. This allows our platform to make automated changes to the IT system, in particular, to replace running components of the system with fresh new instances. To evaluate MTD CBITS' practicality, we present a series of experiments that show negligible (statistically non-significant) performance impacts. To evaluate effectiveness, we analyze the costs and security benefits of MTD CBITS using a practical attack window model and show how a system managed using MTD CBITS will increase attack difficulty.
机译:当前的IT系统的静态特性为攻击者提供了极为宝贵的时间优势,因为攻击者可以随意利用它们的时间来计划攻击时间。尽管云基础架构增加了用于管理IT系统的自动化选项,但是在整个IT系统级别引入移动目标防御(MTD)技术仍然非常具有挑战性。 MTD的核心思想是主动更改系统,以消除攻击者按时获得的非对称优势。但是,由于IT系统组件之间的依存关系的数量和复杂性,在不中断系统或不严重影响其性能的情况下进行主动更改并不容易。在本文中,我们为基于云的IT系统(MTD CBITS)提供了一个MTD平台,评估了其实用性,并对其安全性优势进行了详细分析。据我们所知,MTD CBITS是第一个利用云自动化框架(ANCOR)的优势的MTD平台,该框架使用高级抽象捕获IT系统的设置参数和相关性。这使我们的平台可以对IT系统进行自动更改,特别是可以用新的新实例替换系统中正在运行的组件。为了评估MTD CBITS的实用性,我们提出了一系列实验,这些实验表明对性能的影响可以忽略不计(统计上不重要)。为了评估有效性,我们使用实用的攻击窗口模型分析了MTD CBITS的成本和安全优势,并展示了使用MTD CBITS管理的系统将如何增加攻击难度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号