首页> 外文会议>Annual Hawaii International Conference on System Sciences >Balancing Safety Against Performance: Tradeoffs in Internet Security
【24h】

Balancing Safety Against Performance: Tradeoffs in Internet Security

机译:平衡安全性能:互联网安全的权衡

获取原文
获取外文期刊封面目录资料

摘要

All Internet-accessible computing systems are currently faced with incessant threats ranging from simple script-kiddies to highly sophisticated criminal enterprises. In response to these threats, sites must perform extensive intrusion monitoring. This intrusion monitoring can have significant costs in terms of bandwidth, computing power, storage space, and licensing fees. Furthermore, when exploits are detected, the victims must take actions that can consume further resources and compromise their objectives (e.g., by reducing e-commerce server throughput). In this paper, we explore techniques for modeling the costs and benefits of various security monitoring and response actions. Given these models and stochastic expectations about the types of attacks that a site is likely to face, our CIRCADIA automatic security control system is able to make real-time tradeoffs between the level of safety and security that is enforced, and the level of system resources/performance that are applied to the main computational objectives (e.g., e-commerce transactions). We show how CIRCADIA is able to dynamically adjust its security activities to account for changing threat profiles and objectives. The result: a continually-optimized balance of security-maintaining activity that reduces risk while still allowing the system to meet its goals.
机译:所有互联网可访问的计算系统目前面临不间断的威胁,从简单的脚本 - 童那里到高度复杂的犯罪企业。为了响应这些威胁,网站必须进行广泛的入侵监控。这种入侵监控可能在带宽,计算电源,存储空间和许可费方面具有大量成本。此外,当检测到漏洞时,受害者必须采取可能消耗进一步资源的行动并损害其目标(例如,通过减少电子商务服务器吞吐量)。在本文中,我们探讨了建模各种安全监测和响应行动的成本和益处的技术。鉴于这些模型和随机期望有关网站可能面临的攻击类型,我们的Circadia自动安全控制系统能够在强制执行的安全和安全水平之间进行实时权衡,以及系统资源的水平/适用于主要计算目标的性能(例如,电子商务交易)。我们展示Circadia如何能够动态调整其安全活动,以便更改威胁性概况和目标。结果:不断优化的安全维护活动余额,以降低风险,同时仍然允许系统满足其目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号