位置:成果数据库 > 期刊 > 期刊详情页
一种基于Bio-PEPA的分布式虚拟化系统脆弱性扩散模型
  • ISSN号:0254-4164
  • 期刊名称:《计算机学报》
  • 时间:0
  • 分类:TP309[自动化与计算机技术—计算机系统结构;自动化与计算机技术—计算机科学与技术]
  • 作者机构:哈尔滨工程大学计算机科学与技术学院,哈尔滨150001
  • 相关基金:国家自然科学基金(61402127,61370212); 黑龙江省自然科学基金(F2015029)资助
中文摘要:

脆弱点类型差异和脆弱性演化对脆弱性扩散过程具有显著影响,而现有脆弱性扩散模型对此还缺少深入研究.该文提出一种基于分簇思想的分布式虚拟化系统脆弱性扩散模型,首先按照节点包含脆弱点类型的不同进行分簇,其次利用Bio-PEPA静态分层特性,对脆弱性在簇内、簇间传播,以及簇间迁移演化过程进行建模.最后,将Bio-PEPA模型转化为常微分方程求解,分析分布式虚拟化系统脆弱性扩散的特点和规律,避免了传统分析方法的状态空间爆炸问题.实验结果显示,可以通过提升系统修复能力、降低簇间传播速率、减小簇间变迁速率,抑制分布式虚拟化系统的脆弱性扩散.

英文摘要:

Vulnerability is usually the essential reason of security and dependability. Recently, enormous amounts of third-party applications appear on distributed virtualized systems, which bring out a lot of additional vulnerabilities even more than the inherent vulnerabilities in the systems. Meanwhile, the vulnerabilities are propagated rapidly by frequent interactions and unreasonable trust relationship among nodes. Vulnerability propagation has grown up to be a serious problem. Different types of vulnerabilities and vulnerability evolution have a significant impact on the process of vulnerability propagation, but the existing vulnerability propagation models have not considered these issues. In order to make the model more reasonable, we propose a new vulnerability propagation model for distributed virtualized systems based on clustering. In this model, the same kind of vulnerabilities is regarded as in a single cluster, and then the vulnerability propagation in/between clusters as well as vulnerability migration between clusters is modeled by Bio-PEPA (Performance Evaluation Process Algebra) in a static hierarchy manner. Besides, the Bio-PEPA model we have proposed is converted into ODEs (Original Differential Equations) to discover the law of vulnerability propagation, avoiding the state space explosion existing in traditional analysis methods. The experimental results show that the vulnerability propagation progress can be retained by enhancing the recovery capability, decreasing the rate of vulnerability propagation and reducing the rate of vulnerability migration between clusters. Our works provide an insight into the nature of the vulnerability propagation of distributed virtualized systems, and it is useful to improve the security of the systems.

同期刊论文项目
同项目期刊论文
期刊信息
  • 《计算机学报》
  • 北大核心期刊(2011版)
  • 主管单位:中国科学院
  • 主办单位:中国计算机学会 中国科学院计算技术研究所
  • 主编:孙凝晖
  • 地址:北京中关村科学院南路6号
  • 邮编:100190
  • 邮箱:cjc@ict.ac.cn
  • 电话:010-62620695
  • 国际标准刊号:ISSN:0254-4164
  • 国内统一刊号:ISSN:11-1826/TP
  • 邮发代号:2-833
  • 获奖情况:
  • 中国期刊方阵“双效”期刊
  • 国内外数据库收录:
  • 美国数学评论(网络版),荷兰文摘与引文数据库,美国工程索引,美国剑桥科学文摘,日本日本科学技术振兴机构数据库,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版),中国北大核心期刊(2000版)
  • 被引量:48433