首页> 外文会议>Future Technologies Conference >Mitigating service impersonation attacks in clouds
【24h】

Mitigating service impersonation attacks in clouds

机译:减轻云中的服务模仿攻击

获取原文

摘要

Providing security for interacting cloud services requires more than user authentication with passwords or digital certificates and confidentiality in data transmission. Existing data protection mechanisms have previously failed in preventing data theft attacks perpetrated by an insider to the cloud provider or impersonators. In this paper, we focus on the service cloud model, which facilitates the composition and communication among web services owned by different cloud vendors. We augment a detection approach for impersonation attacks with additional analyses to improve the security of communicating web services hosted in the cloud. A statistical model generates a normal behavior profile for individual services and groups of services based on their business tasks. The detection approach monitors the behavior of each service and identifies anomalies as a potential impersonation attack if it deviates significantly from the expected behavior. To verify the impersonation attack, we deploy a cloud-based verification technique, misleading suspicious services with useless responses. The experimental results show that modeling request behavior reliably detects a significant number of impersonation attempts, with a performance degradation that is a reasonable trade-off.
机译:为交互云服务提供安全性,需要使用密码或数字证书和数据传输中的机密性的用户身份验证。现有的数据保护机制以前失败,防止内部人员犯下了云提供商或模拟器的数据盗窃攻击。在本文中,我们专注于服务云模型,这促进了不同云供应商拥有的Web服务之间的组成和通信。我们增强了额外分析的模拟攻击的检测方法,以提高云中托管的网络服务的安全性。统计模型基于业务任务为各个服务和服务组生成正常行为配置文件。检测方法监视每个服务的行为,如果它从预期行为显着偏离,则将异常识别为潜在的模拟攻击。为了验证模拟攻击,我们部署了一种基于云的验证技术,误导了可用的服务与无用的响应。实验结果表明,建模请求行为可靠地检测到大量的冒充尝试,具有性能下降,即合理的权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号