首页> 外文期刊>Computer networks >Automated adaptive intrusion containment in systems of interacting services
【24h】

Automated adaptive intrusion containment in systems of interacting services

机译:交互服务系统中的自动自适应入侵遏制

获取原文
获取原文并翻译 | 示例

摘要

Large scale distributed systems typically have interactions among different services that create an avenue for propagation of a failure from one service to another. The failures being considered may be the result of natural failures or malicious activity, collectively called disruptions. To make these systems tolerant to failures it is necessary to contain the spread of the occurrence automatically once it is detected. The objective is to allow certain parts of the system to continue to provide partial functionality in the system in the face of failures. Real world situations impose several constraints on the design of such a disruption tolerant system of which we consider the following - the alarms may have type Ⅰ or type Ⅱ errors; it may not be possible to change the service itself even though the interaction may be changed; attacks may use steps that are not anticipated a priori; and there may be bursts of concurrent alarms. We present the design and implementation of a system named ADEPTS as the realization of such a disruption tolerant system. ADEPTS uses a directed graph representation to model the spread of the failure through the system, presents algorithms for determining appropriate responses and monitoring their effectiveness, and quantifies the effect of disruptions through a high level survivability metric. ADEPTS is demonstrated on a real e-commerce testbed with actual attack patterns injected into it.
机译:大型分布式系统通常在不同服务之间进行交互,从而为从一个服务到另一个服务的故障传播创造了一条途径。考虑的故障可能是自然故障或恶意活动(统称为中断)的结果。为了使这些系统能够容忍故障,必须在检测到事件后自动遏制事件的蔓延。目的是允许系统的某些部分在出现故障时继续在系统中提供部分功能。现实世界的情况对这种容错系统的设计施加了一些限制,我们考虑以下因素:警报可能具有Ⅰ类或Ⅱ类错误;即使交互可能已更改,也可能无法更改服务本身;攻击可能会使用事先无法预期的步骤;并且可能会出现并发警报。我们介绍了一个名为ADEPTS的系统的设计和实现,以实现这种容错系统。 ADEPTS使用有向图表示法对整个系统中的故障传播进行建模,提出用于确定适当响应和监视其有效性的算法,并通过高级生存性度量来量化中断的影响。 ADEPTS在真实的电子商务测试平台上进行了演示,并在其中注入了实际的攻击模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号