...
首页> 外文期刊>International Journal on Critical Infrastructure Protection >Creating a cyber moving target for critical infrastructure applications using platform diversity
【24h】

Creating a cyber moving target for critical infrastructure applications using platform diversity

机译:使用平台多样性为关键基础架构应用程序创建网络移动目标

获取原文
获取原文并翻译 | 示例

摘要

Despite the significant effort that often goes into securing critical infrastructure assets, many systems remain vulnerable to advanced, targeted cyber attacks. This paper describes the design and implementation of the Trusted Dynamic Logical Heterogeneity System (TALENT), a framework for live-migrating critical infrastructure applications across heterogeneous platforms. TALENT permits a running critical application to change its hardware platform and operating system, thus providing cyber survivability through platform diversity. TALENT uses containers (operating-system-level virtualization) and a portable checkpoint compiler to create a virtual execution environment and to migrate a running application across different platforms while preserving the state of the application (execution state, open files and network connections). TALENT is designed to support general applications written in the C programming language. By changing the platform on-the-fly, TALENT creates a cyber moving target and significantly raises the bar for a successful attack against a critical application. Experiments demonstrate that a complete migration can be completed within about one second.
机译:尽管经常花费大量精力来保护关键基础设施资产,但许多系统仍然容易受到高级针对性网络攻击的攻击。本文描述了可信动态逻辑异构系统(TALENT)的设计和实现,该框架是跨异构平台实时迁移关键基础设施应用程序的框架。 TALENT允许运行中的关键应用程序更改其硬件平台和操作系统,从而通过平台多样性提供网络生存能力。 TALENT使用容器(操作系统级虚拟化)和便携式检查点编译器来创建虚拟执行环境并在不同平台之间迁移正在运行的应用程序,同时保留应用程序的状态(执行状态,打开的文件和网络连接)。 TALENT旨在支持使用C编程语言编写的常规应用程序。通过动态更改平台,TALENT创建了网络移动目标,并大大提高了成功攻击关键应用程序的标准。实验表明,完整的迁移可以在大约一秒钟内完成。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号