首页> 外文期刊>Software >Security Benchmarks Of Osgi Platforms: Toward Hardened Osgi
【24h】

Security Benchmarks Of Osgi Platforms: Toward Hardened Osgi

机译:Osgi平台的安全基准:迈向强化的Osgi

获取原文
获取原文并翻译 | 示例
       

摘要

OSGi platforms are extensible component platforms, i.e. they support the dynamic and transparent installation of components that are provided by third party providers at runtime. This feature makes systems built using OSGi extensible and adaptable, but opens a dangerous attack vector that has not been considered as such until recently. Performing a security benchmark of the OSGi platform is therefore necessary to gather knowledge related to the weaknesses it introduces as well as to propose enhancements. A suitable Vulnerability Pattern is defined. The attacks that can be performed through malicious OSGi components are identified. Quantitative analysis is then performed so as to characterize the origin of the vulnerabilities and the target and consequences of the attacks. The assessment of the security status of the various implementations of the OSGi platform and of existing security mechanisms is done through a metric we introduce, the Protection rate (PR). Based on these benchmarks, OSGi-speciflc security enhancements are identified and evaluated. First recommendations are given. Then evaluation is performed through the PR metric and performance analysis. Lastly, further requirements for building secure OSGi platforms are identified.
机译:OSGi平台是可扩展的组件平台,即它们支持由第三方提供商在运行时提供的动态透明的组件安装。此功能使使用OSGi构建的系统具有可扩展性和适应性,但打开了直到最近才被认为是危险的攻击媒介。因此,有必要执行OSGi平台的安全性基准测试,以收集与其引入的弱点有关的知识并提出增强建议。定义了合适的漏洞模式。确定可以通过恶意OSGi组件执行的攻击。然后进行定量分析,以表征漏洞的来源以及攻击的目标和后果。 OSGi平台的各种实现和现有安全机制的安全状态评估是通过我们引入的指标即保护率(PR)进行的。基于这些基准,可以识别和评估OSGi特定的安全性增强功能。首先给出建议。然后通过PR指标和绩效分析进行评估。最后,确定了构建安全OSGi平台的进一步要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号