首页> 外文期刊>ACM transactions on computer systems >EventGuard: A System Architecture for Securing Publish-Subscribe Networks
【24h】

EventGuard: A System Architecture for Securing Publish-Subscribe Networks

机译:EventGuard:用于保护发布-订阅网络的系统体系结构

获取原文
获取原文并翻译 | 示例

摘要

Publish-subscribe (pub-sub) is an emerging paradigm for building a large number of distributed systems. A wide area pub-sub system is usually implemented on an overlay network infrastructure to enable information dissemination from publishers to subscribers. Using an open overlay network raises several security concerns such as: confidentiality and integrity, authentication, authorization and Denial-of-Service (DoS) attacks. In this article we present EventGuard, a framework for building secure wide-area pub-sub systems. The EventGuard architecture is comprised of three key components: (1) a suite of security guards that can be seamlessly plugged-into a content-based pub-sub system, (2) a scalable key management algorithm to enforce access control on subscribers, and (3) a resilient pub-sub network design that is capable of scalable routing, handling message dropping-based DoS attacks, and node failures. The design of EventGuard mechanisms aims at providing security guarantees while maintaining the system's overall simplicity, scalability, and performance metrics. We describe an implementation of the EventGuard pub-sub system to show that EventGuard is easily stackable on any content-based pub-sub core. We present detailed experimental results that quantify the overhead of the EventGuard pub-sub system and demonstrate its resilience against various attacks.
机译:发布-订阅(pub-sub)是用于构建大量分布式系统的新兴范例。广域发布-订阅系统通常在覆盖网络基础结构上实现,以实现从发布者到订阅者的信息传播。使用开放式覆盖网络会引起一些安全问题,例如:机密性和完整性,身份验证,授权和拒绝服务(DoS)攻击。在本文中,我们介绍EventGuard,这是一个用于构建安全的广域发布-订阅系统的框架。 EventGuard体系结构由三个关键组件组成:(1)一套可以无缝插入基于内容的发布-订阅系统的安全卫士;(2)一种可伸缩的密钥管理算法,用于对订户执行访问控制;以及(3)弹性的发布-订阅网络设计,能够进行可扩展的路由,处理基于消息丢弃的DoS攻击和节点故障。 EventGuard机制的设计旨在提供安全保证,同时保持系统的整体简单性,可伸缩性和性能指标。我们描述了EventGuard pub-sub系统的实现,以显示EventGuard可以轻松堆叠在任何基于内容的pub-sub核心上。我们提供详细的实验结果,以量化EventGuard pub-sub系统的开销并证明其对各种攻击的抵抗力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号