首页> 外文期刊>IEICE transactions on information and systems >Hybrid Recovery-Based Intrusion Tolerant System for Practical Cyber-Defense
【24h】

Hybrid Recovery-Based Intrusion Tolerant System for Practical Cyber-Defense

机译:基于混合恢复的实用网络防御入侵容忍系统

获取原文
           

摘要

Due to the periodic recovery of virtual machines regardless of whether malicious intrusions exist, proactive recovery-based Intrusion Tolerant Systems (ITSs) are being considered for mission-critical applications. However, the virtual replicas can easily be exposed to attacks during their working period, and additionally, proactive recovery-based ITSs are ineffective in eliminating the vulnerability of exposure time, which is closely related to service availability. To address these problems, we propose a novel hybrid recovery-based ITS in this paper. The proposed method utilizes availability-driven recovery and dynamic cluster resizing. The availability-driven recovery method operates the recovery process by both proactive and reactive ways for the system to gain shorter exposure times and higher success rates. The dynamic cluster resizing method reduces the overhead of the system that occurs from dynamic workload fluctuations. The performance of the proposed ITS with various synthetic and real workloads using CloudSim showed that it guarantees higher availability and reliability of the system, even under malicious intrusions such as DDoS attacks.
机译:由于虚拟机的定期恢复(无论是否存在恶意入侵),正在针对任务关键型应用程序考虑基于主动恢复的入侵容忍系统(ITS)。但是,虚拟副本在其工作期间很容易受到攻击,此外,基于主动恢复的ITS无法有效消除与服务可用性密切相关的暴露时间的脆弱性。为了解决这些问题,我们在本文中提出了一种基于混合恢复的新型ITS。所提出的方法利用了可用性驱动的恢复和动态集群大小调整。可用性驱动的恢复方法通过主动和被动方式来操作恢复过程,以使系统获得更短的曝光时间和更高的成功率。动态群集大小调整方法可减少由于动态工作负载波动而产生的系统开销。拟议的ITS在使用CloudSim的各种合成和实际工作负载下的性能表明,即使在DDoS攻击等恶意入侵下,它也可以保证系统的更高可用性和可靠性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号