首页> 外文会议>Association for Computing Machinery Conference on Computer and Communications Security >On Achieving Software Diversity for Improved Network Security using Distributed Coloring Algorithms
【24h】

On Achieving Software Diversity for Improved Network Security using Distributed Coloring Algorithms

机译:用分布式着色算法实现改进网络安全的软件多样性

获取原文

摘要

It is widely believed that diversity in operating systems, software packages, and hardware platforms will decrease the virulence of worms and the effectiveness of repeated applications of single attacks. Research efforts in the field have focused on introducing diversity using a variety of techniques on a system-by-system basis. This paper, on the other hand, assumes the availability of diverse software packages for each system and then seeks to increase the intrinsic value of available diversity by considering the entire computer network. We present several distributed algorithms for the assignment of distinct software packages to individual systems and analyze their performance. Our goal is to limit the ability of a malicious node to use a single attack to compromise its neighboring nodes, and by extension, the rest of the nodes in the network. The algorithms themselves are analyzed for attack tolerance, and strategies for improving the security of the individual software assignment schemes are presented. We present a comparative analysis of our algorithms using simulation results on a topology obtained from e-mail traffic logs between users at our institution. We find that hybrid versions of our algorithms incorporating multiple assignment strategies achieve better attack tolerance than any given assignment strategy, Our work thus shows that diversity must be introduced at all levels of system design, including any scheme that is used to introduce diversity itself.
机译:人们普遍认为,操作系统,软件包和硬件平台中的多样性将降低蠕虫的毒力和单一攻击的重复应用的有效性。该领域的研究努力专注于在系统基础上使用各种技术引入多样性。另一方面,本文假设每个系统的不同软件包的可用性,然后通过考虑整个计算机网络来寻求增加可用多样性的内在值。我们为各个系统提供了几种分布式算法,以分配不同的软件包并分析其性能。我们的目标是限制恶意节点使用单一攻击来危害其相邻节点的能力,并通过扩展,网络中的其余部分。分析了算法本身的攻击公差,并介绍了提高各个软件分配方案的安全的策略。我们向我们在我们机构的用户之间获得的电子邮件流量日志中获得的拓扑结构,对我们的算法提供了对我们的算法的比较分析。我们发现,通过任何给定的任务策略,我们的工作都显示出多种分配策略的算法的混合版本,从而实现了比任何给定的分配策略更好的攻击容忍度,因此表明必须在各级系统设计中引入多样性,包括用于引入多样性本身的方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号