首页> 外文会议>European Symposium on Research in Computer Security >MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
【24h】

MTD CBITS: Moving Target Defense for Cloud-Based IT Systems

机译:MTD Cbits:移动基于云IT系统的目标防御

获取原文

摘要

The static nature of current IT systems gives attackers the extremely valuable advantage of time, as adversaries can take their time and plan attacks at their leisure. Although cloud infrastructures have increased the automation options for managing IT systems, the introduction of Moving Target Defense (MTD) techniques at the entire IT system level is still very challenging. The core idea of MTD is to make a system change proactively as a means to eliminating the asymmetric advantage the attacker has on time. However, due to the number and complexity of dependencies between IT system components, it is not trivial to introduce proactive changes without breaking the system or severely impacting its performance. In this paper, we present an MTD platform for Cloud-Based IT Systems (MTD CBITS), evaluate its practicality, and perform a detailed analysis of its security benefits. To the best of our knowledge MTD CBITS is the first MTD platform that leverages the advantages of a cloud-automation framework (ANCOR) that captures an IT system's setup parameters and dependencies using a high-level abstraction. This allows our platform to make automated changes to the IT system, in particular, to replace running components of the system with fresh new instances. To evaluate MTD CBITS' practicality, we present a series of experiments that show negligible (statistically non-significant) performance impacts. To evaluate effectiveness, we analyze the costs and security benefits of MTD CBITS using a practical attack window model and show how a system managed using MTD CBITS will increase attack difficulty.
机译:当前IT系统的静态性质为攻击者提供了极其宝贵的时间,因为对手可能会花时间和计划休闲袭击。虽然云基础架构增加了管理IT系统的自动化选项,但在整个IT系统级别的移动目标防御(MTD)技术的引入仍然非常具有挑战性。 MTD的核心思想是使系统主动变化,作为消除攻击者准时的不对称优势的手段。但是,由于IT系统组件之间的依赖性的数量和复杂性,因此在不打破系统的情况下或严重影响其性能而不打破系统而导致积极的变化并不重要。在本文中,我们为云的IT系统(MTD Cbits)提供了一个MTD平台,评估其实用性,并对其安全益处进行详细分析。据我们所知,MTD Cbits是第一个利用云自动化框架(AUTOR)的优势,它使用高级抽象捕获IT系统的设置参数和依赖项的优势。这允许我们的平台对IT系统进行自动化,特别是用新的新实例替换系统的运行组件。为了评估MTD CBITS的实用性,我们提出了一系列实验,显示出可忽略的(统计上不显着的)性能影响。为了评估效果,我们使用实际攻击窗口模型分析MTD CBITS的成本和安全益处,并展示如何使用MTD CBITS管理的系统将增加攻击难度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号