首页> 外文期刊>Computers & Security >Invi-server: Reducing the attack surfaces by making protected server invisible on networks
【24h】

Invi-server: Reducing the attack surfaces by making protected server invisible on networks

机译:Invi-server:通过使受保护的服务器在网络上不可见来减少攻击面

获取原文
获取原文并翻译 | 示例

摘要

The advantage of having remote access motivates network administrators to connect mission-critical servers (e.g., enterprise management systems) as well as public web servers via the Internet, even though connecting these mission-critical servers to the Internet is not recommended. These mission-critical or public servers are accessible from any host on the Internet, allowing cyber attackers to engage the targeted server as part of a process to discover potential exploits and unpatched vulnerabilities. Although it would be difficult to eradicate all the potential vulnerabilities in advance, accessibility to a server can be controlled to limit or minimize the chance of exposing a vulnerable surface. We aimed to address the accessibility issue by designing and prototyping an Invi-server system, in which the IP and MAC addresses of the protected secret server remain invisible from external scanning and eavesdropping trials and even from compromised internal hosts on the network. This Invi-server system can be used as a way to reduce the attack surface of a protected server while allowing authorized users to send and receive packets via the protected server. We also implemented a prototype of the Invi-server system to demonstrate that our proposed system has the ability to reduce the attack surfaces significantly without increasing network performance overhead to any significant extent.
机译:尽管不建议将这些关键任务服务器连接到Internet,但是具有远程访问的优势促使网络管理员通过Internet连接关键任务服务器(例如,企业管理系统)和公共Web服务器。可以从Internet上的任何主机访问这些关键任务或公共服务器,从而使网络攻击者可以将目标服务器用作发现潜在漏洞和未修补漏洞的过程的一部分。尽管很难预先消除所有潜在的漏洞,但是可以控制对服务器的访问权限,以限制或最小化暴露易受攻击的表面的机会。我们旨在通过设计和制作Invi服务器系统原型来解决可访问性问题,在该系统中,受保护的秘密服务器的IP地址和MAC地址对于外部扫描和窃听试验甚至对网络上受感染的内部主机而言都是不可见的。该Invi服务器系统可用作减少受保护服务器的攻击面的方法,同时允许授权用户通过受保护服务器发送和接收数据包。我们还实现了Invi服务器系统的原型,以证明我们提出的系统能够在不显着增加网络性能开销的情况下,大大减少攻击面。

著录项

  • 来源
    《Computers & Security》 |2017年第6期|89-106|共18页
  • 作者单位

    School of Computing, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 34141, Republic of Korea;

    School of Computing, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 34141, Republic of Korea;

    School of Computing, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 34141, Republic of Korea;

    School of Computing, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 34141, Republic of Korea;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Invisible authentication; Server security; Covert channel; Secret server; One-time password;

    机译:隐形身份验证;服务器安全性;隐秘渠道;秘密服务器;一次性密码;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号