...
首页> 外文期刊>IEEE systems journal >ProtoGENI, a Prototype GENI Under Security Vulnerabilities: An Experiment-Based Security Study
【24h】

ProtoGENI, a Prototype GENI Under Security Vulnerabilities: An Experiment-Based Security Study

机译:ProtoGENI,处于安全漏洞下的原型GENI:基于实验的安全性研究

获取原文
获取原文并翻译 | 示例
           

摘要

ProtoGENI is one of the prototype implementations of global environment for network innovations (GENI). ProtoGENI proposes and executes the GENI control framework, including resource management and allocation for authenticated and authorized experimenters. Security and inevitably are the most important concerns in the whole development process. In this paper, we study and evaluate its security vulnerabilities according to GENI's security goals. We analyze the threat model of ProtoGENI and categorize four broad classes of attacks. Based on the role of an active experimenter, we demonstrate experiments as proof of the concept that each class of attacks can be successfully launched using common open source network tools. We also present analysis and experiments that show perspectives on the potential risks from an external user. Furthermore, we discuss the feasibility and possible defense strategies on ProtoGENI security with respect to our preliminary experiments and potential future directions. Our contribution lies in examining known vulnerabilities without requiring sophisticated experiments while remaining effective. We have reported our findings to the ProtoGENI Team. Our work indicates that the solutions have been deployed. This paper validates that experiment-based vulnerability exploration is necessary.
机译:ProtoGENI是网络创新全球环境(GENI)的原型实现之一。 ProtoGENI提出并执行了GENI控制框架,包括资源管理以及对经过身份验证和授权的实验者的分配。安全,不可避免地是整个开发过程中最重要的问题。在本文中,我们根据GENI的安全目标来研究和评估其安全漏洞。我们分析了ProtoGENI的威胁模型,并将攻击分为四大类。基于活跃实验者的角色,我们演示了实验,以此证明可以使用常见的开源网络工具成功发起各种攻击。我们还提供了分析和实验,它们显示了来自外部用户的潜在风险的观点。此外,关于我们的初步实验和潜在的未来方向,我们讨论了ProtoGENI安全性的可行性和可能的​​防御策略。我们的贡献在于,在保持有效的同时,无需复杂的实验即可检查已知漏洞。我们已将发现的结果报告给ProtoGENI小组。我们的工作表明解决方案已经部署。本文验证了基于实验的漏洞探索是必要的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号