计算机研究与发展
計算機研究與髮展
계산궤연구여발전
JOURNAL OF COMPUTER RESEARCH AND DEVELOPMENT
2010年
3期
493-499
,共7页
赵峰%金海%金莉%袁平鹏
趙峰%金海%金莉%袁平鵬
조봉%금해%금리%원평붕
入侵容忍%虚拟计算%系统安全%序列预测%系统调用
入侵容忍%虛擬計算%繫統安全%序列預測%繫統調用
입침용인%허의계산%계통안전%서렬예측%계통조용
intrusion tolerance%virtual computing%system security%sequence forecast%system call
虚拟计算环境的开放性、复杂性和动态性向入侵容忍提出了新的挑战,提出VFRS方法以解决虚拟计算环境中数据对入侵的容忍问题.设计SCSFA算法分析虚拟计算环境的系统调用行为序列,以识别虚拟计算环境下的入侵企图,预测敏感数据的高危区域;其次,将要保护的数据划分成若干片数据,并以容忍虚拟计算环境随机错误为目标对每个片数据冗余备份;然后将冗余片数据分散到不同虚拟机上.VFRS方法能有效预测虚拟计算环境下的异常入侵,并能较好地容忍虚拟计算环境下的复杂性错误.对VFRS 方法实现的关键问题进行了详细的讨论和分析.
虛擬計算環境的開放性、複雜性和動態性嚮入侵容忍提齣瞭新的挑戰,提齣VFRS方法以解決虛擬計算環境中數據對入侵的容忍問題.設計SCSFA算法分析虛擬計算環境的繫統調用行為序列,以識彆虛擬計算環境下的入侵企圖,預測敏感數據的高危區域;其次,將要保護的數據劃分成若榦片數據,併以容忍虛擬計算環境隨機錯誤為目標對每箇片數據冗餘備份;然後將冗餘片數據分散到不同虛擬機上.VFRS方法能有效預測虛擬計算環境下的異常入侵,併能較好地容忍虛擬計算環境下的複雜性錯誤.對VFRS 方法實現的關鍵問題進行瞭詳細的討論和分析.
허의계산배경적개방성、복잡성화동태성향입침용인제출료신적도전,제출VFRS방법이해결허의계산배경중수거대입침적용인문제.설계SCSFA산법분석허의계산배경적계통조용행위서렬,이식별허의계산배경하적입침기도,예측민감수거적고위구역;기차,장요보호적수거화분성약간편수거,병이용인허의계산배경수궤착오위목표대매개편수거용여비빈;연후장용여편수거분산도불동허의궤상.VFRS방법능유효예측허의계산배경하적이상입침,병능교호지용인허의계산배경하적복잡성착오.대VFRS 방법실현적관건문제진행료상세적토론화분석.
With the emergence of multi-core processor,virtualization technology has attracted attention and developed rapidly in recent years.Virtual computing environment based on virtual machine becomes a hot topic in the field of network computing.Virtual computing environment is open,complex and dynamic,which has brought new challenges to system security,especially to intrusion tolerance.In this paper,VFRS method is proposed in order to protect sensitive data from intrusion in virtual computing environment.Firstly,a probability computing model is constructed to present system call sequences and the SCSFA algorithm is designed to predict the attempt of intrusion and to determine what need to protect,which is based on the analysis of system call sequence in virtual computing systems; Secondly,the sensitive data protected are divided into a number of film data,and for the goals of random errors tolerance,each tablet data are redundant backup based on Byzantine fault tolerance; Then,the redundant data are distributed to different virtual machines.VFRS method can predict the anomaly intrusion and well tolerate the complicated errors in virtual computing environment.The experimental results show that VFRS is effective and of high performance compared with related work.Some key issues of the VFRS method are also discussed and analyzed in detail.