首页> 外文会议>IEEE International Conference on Software Architecture >Component-Based Refinement and Verification of Information-Flow Security Policies for Cyber-Physical Microservice Architectures
【24h】

Component-Based Refinement and Verification of Information-Flow Security Policies for Cyber-Physical Microservice Architectures

机译:基于组件的网络物理微服务体系结构信息流安全策略的细化和验证

获取原文

摘要

Since cyber-physical systems are inherently vulnerable to information leaks, software architects need to reason about security policies to define desired and undesired information flow through a system. The microservice architectural style requires the architects to refine a macro-level security policy into micro-level policies for individual microservices. However, when policies are refined in an ill-formed way, information leaks can emerge on composition of microservices. Related approaches to prevent such leaks do not take into account characteristics of cyber-physical systems like real-time behavior or message passing communication. In this paper, we enable the refinement and verification of information-flow security policies for cyber-physical microservice architectures. We provide architects with a set of well-formedness rules for refining a macro-level policy in a way that enforces its security restrictions. Based on the resulting micro-level policies, we present a verification technique to check if the real-time message passing of microservices is secure. In combination, our contributions prevent information leaks from emerging on composition. We evaluate the accuracy of our approach using an extension of the CoCoME case study.
机译:由于网络物理系统本质上容易受到信息泄漏的影响,因此软件架构需要推理安全策略来定义通过系统的期望和不期望的信息流。微服务架构风格要求架构师将宏观级安全策略优化到单个微服务的微级策略中。但是,当以不成本的方式精制策略时,可以出现微源的组成。防止这种泄漏的相关方法不考虑网络物理系统的特征,如实时行为或消息传递通信。在本文中,我们可以改进和验证网络物理微服务架构的信息流安全策略。我们提供具有一组良好成本性规则的架构师,用于以实施其安全限制的方式精炼宏观级别策略。基于由此产生的微级策略,我们提出了一种验证技术来检查微猎狼的实时消息是否安全。组合,我们的贡献防止了信息泄漏了组成。我们使用通勤案例研究的延伸评估我们方法的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号