首页> 外文期刊>Cloud Computing, IEEE Transactions on >On the Design and Implementation of an Integrated Security Architecture for Cloud with Improved Resilience
【24h】

On the Design and Implementation of an Integrated Security Architecture for Cloud with Improved Resilience

机译:具有增强的弹性的云集成安全体系结构的设计和实现

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we propose an integrated security architecture which combines policy based access control with intrusion detection techniques and trusted computing technologies for securing distributed applications running on virtualised systems. Our security architecture incorporates access control security policies for secure interactions between applications and virtual machines in different physical virtualized servers. It provides intrusion detection and trusted attestation techniques to detect and counteract dynamic attacks in an efficient manner. We demonstrate how this integrated security architecture is used to secure the life cycle of virtual machines including dynamic hosting and allocation of resources as well as migration of virtual machines across different physical servers. We discuss the implementation of the developed architecture and show how the architecture can counteract attack scenarios involving malicious users exploiting vulnerabilities to achieve privilege escalation and then using the compromised machines to generate further attacks. The feedback between the various security components of our security architecture plays a critical role in detecting sophisticated, dynamically changing attacks, thereby increasing the resilience of the overall secure system.
机译:在本文中,我们提出了一种集成的安全体系结构,该体系结构将基于策略的访问控制与入侵检测技术和可信计算技术相结合,以保护在虚拟化系统上运行的分布式应用程序的安全。我们的安全体系结构包含访问控制安全策略,用于在不同物理虚拟服务器中的应用程序和虚拟机之间进行安全交互。它提供了入侵检测和可信证明技术,可以有效地检测和抵制动态攻击。我们将演示如何使用这种集成的安全体系结构来保护虚拟机的生命周期,包括动态托管和资源分配以及跨不同物理服务器的虚拟机迁移。我们讨论了所开发体系结构的实现,并展示了该体系结构如何抵消涉及恶意用户利用漏洞来实现特权升级,然后使用受感染计算机生成进一步攻击的攻击方案。我们的安全体系结构的各个安全组件之间的反馈在检测复杂的,动态变化的攻击中扮演着至关重要的角色,从而提高了整个安全系统的弹性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号