首页> 外文会议>INFOCOM 2000. Nineteenth Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE >MarketNet: market-based protection of network systems and services-an application to SNMP protection
【24h】

MarketNet: market-based protection of network systems and services-an application to SNMP protection

机译:MarketNet:基于市场的网络系统和服务保护-SNMP保护的应用

获取原文

摘要

This paper describes novel protection technologies, developed by the MarketNet project at Columbia University, that shifts power from attackers to defenders, giving the defenders control over the exposure to attacks and over detectability and accountability of attackers. MarketNet uses market-based techniques to regulate access to resources. Access to a resource must be paid-for with currency issued by its domain. Domains can control the power of attackers by limiting the budgets allocated to them, and control the exposure of resources by setting their prices, effectively providing a quantifiable access control mechanism. Domains can monitor currency flows and use uniform resource-independent statistical algorithms to correlate and detect access anomalies indicating potential attacks. Currency is marked with unique identifiers that permit domains to establish verifiable accountability in accessing their resources. Domains control and fine tune their exposure to attacks; adjust this exposure in response to emerging risks; detect intrusion attacks through automated, uniform statistical analysis of currency flows; and establish coordinated response to attacks. MarketNet mechanisms unify and kernelize global information systems protection by containing all protection logic in a small core of software components. The paper presents the architecture and operation of MarketNet along with the design and implementation of the main architectural components. The paper illustrates the application of MarketNet to the protection of the simple network management protocol (SNMP) and compares it with the security features offered by SNMPv3.
机译:本文介绍了由哥伦比亚大学MarketNet项目开发的新型保护技术,该技术将权力从攻击者转移到了防御者,使防御者可以控制遭受攻击的风险以及攻击者的可检测性和问责制。 MarketNet使用基于市场的技术来规范对资源的访问。对资源的访问必须使用其域发行的货币付费。域可以通过限制分配给他们的预算来控制攻击者的能力,并可以通过设置价格来控制资源的暴露,从而有效地提供可量化的访问控制机制。域可以监视货币流量,并使用统一的,与资源无关的统计算法来关联和检测表明潜在攻击的访问异常。货币用唯一的标识符标记,该标识符允许域在访问其资源时建立可验证的责任制。域控制并微调其受到攻击的可能性;调整风险以应对新出现的风险;通过自动,统一的货币流量统计分析来检测入侵攻击;并建立对攻击的协调响应。 MarketNet机制通过将所有保护逻辑包含在一个小的软件组件核心中来统一和内核化全球信息系统保护。本文介绍了MarketNet的体系结构和操作,以及主要体系结构组件的设计和实现。本文说明了MarketNet在保护简单网络管理协议(SNMP)中的应用,并将其与SNMPv3提供的安全功能进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号