检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:吕宏武[1] 王慧强[1] 林俊宇[1] 冯光升[1] 郭方方[1]
机构地区:[1]哈尔滨工程大学计算机科学与技术学院,哈尔滨150001
出 处:《计算机学报》2016年第2期391-404,共14页Chinese Journal of Computers
基 金:国家自然科学基金(61402127;61370212);黑龙江省自然科学基金(F2015029)资助~~
摘 要:脆弱点类型差异和脆弱性演化对脆弱性扩散过程具有显著影响,而现有脆弱性扩散模型对此还缺少深入研究.该文提出一种基于分簇思想的分布式虚拟化系统脆弱性扩散模型,首先按照节点包含脆弱点类型的不同进行分簇,其次利用Bio-PEPA静态分层特性,对脆弱性在簇内、簇间传播,以及簇间迁移演化过程进行建模.最后,将Bio-PEPA模型转化为常微分方程求解,分析分布式虚拟化系统脆弱性扩散的特点和规律,避免了传统分析方法的状态空间爆炸问题.实验结果显示,可以通过提升系统修复能力、降低簇间传播速率、减小簇间变迁速率,抑制分布式虚拟化系统的脆弱性扩散.Vulnerability is usually the essential reason of security and dependability. Recently, enormous amounts of third-party applications appear on distributed virtualized systems, which bring out a lot of additional vulnerabilities even more than the inherent vulnerabilities in the systems. Meanwhile, the vulnerabilities are propagated rapidly by frequent interactions and unreasonable trust relationship among nodes. Vulnerability propagation has grown up to be a serious problem. Different types of vulnerabilities and vulnerability evolution have a significant impact on the process of vulnerability propagation, but the existing vulnerability propagation models have not considered these issues. In order to make the model more reasonable, we propose a new vulnerability propagation model for distributed virtualized systems based on clustering. In this model, the same kind of vulnerabilities is regarded as in a single cluster, and then the vulnerability propagation in/between clusters as well as vulnerability migration between clusters is modeled by Bio-PEPA (Performance Evaluation Process Algebra) in a static hierarchy manner. Besides, the Bio-PEPA model we have proposed is converted into ODEs (Original Differential Equations) to discover the law of vulnerability propagation, avoiding the state space explosion existing in traditional analysis methods. The experimental results show that the vulnerability propagation progress can be retained by enhancing the recovery capability, decreasing the rate of vulnerability propagation and reducing the rate of vulnerability migration between clusters. Our works provide an insight into the nature of the vulnerability propagation of distributed virtualized systems, and it is useful to improve the security of the systems.
关 键 词:脆弱性分析 脆弱性扩散 分布式虚拟化系统 Bio-PEPA 云计算
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.4