佛山科学技术学院学报(自然科学版)
彿山科學技術學院學報(自然科學版)
불산과학기술학원학보(자연과학판)
Journal of Foshan University (Natural Science Edition)
2015年
6期
64-69
,共6页
杨文茵%马莉%周灵%丁伟雄
楊文茵%馬莉%週靈%丁偉雄
양문인%마리%주령%정위웅
云计算%云安全%入侵检测%蜜罐%Eucalyptus
雲計算%雲安全%入侵檢測%蜜罐%Eucalyptus
운계산%운안전%입침검측%밀관%Eucalyptus
cloud computing%cloud security%intrusion detection%honeypot%Eucalyptus
云计算由于通过因特网提供公共资源般的计算存储服务,而使之暴露于各种网络入侵威胁中。搭建安全云架构以提高云服务的安全性是云安全的首要任务。入侵检测是一种被动防御技术,擅长实时识别已知攻击模式,对未知异常行为的误判率较高。蜜罐是一种主动防御技术,它通过提供虚假信息、系统或网络环境,诱使攻击方实施攻击,从而了解攻击行为并做出相应处理,有利于发现新攻击手段及态势。将入侵检测和蜜罐技术融合到云架构Eucalyptus的方案,可使云端更加安全可靠。
雲計算由于通過因特網提供公共資源般的計算存儲服務,而使之暴露于各種網絡入侵威脅中。搭建安全雲架構以提高雲服務的安全性是雲安全的首要任務。入侵檢測是一種被動防禦技術,擅長實時識彆已知攻擊模式,對未知異常行為的誤判率較高。蜜罐是一種主動防禦技術,它通過提供虛假信息、繫統或網絡環境,誘使攻擊方實施攻擊,從而瞭解攻擊行為併做齣相應處理,有利于髮現新攻擊手段及態勢。將入侵檢測和蜜罐技術融閤到雲架構Eucalyptus的方案,可使雲耑更加安全可靠。
운계산유우통과인특망제공공공자원반적계산존저복무,이사지폭로우각충망락입침위협중。탑건안전운가구이제고운복무적안전성시운안전적수요임무。입침검측시일충피동방어기술,천장실시식별이지공격모식,대미지이상행위적오판솔교고。밀관시일충주동방어기술,타통과제공허가신식、계통혹망락배경,유사공격방실시공격,종이료해공격행위병주출상응처리,유리우발현신공격수단급태세。장입침검측화밀관기술융합도운가구Eucalyptus적방안,가사운단경가안전가고。
Cloud computing services are provided through the Internet, resulting in the exposure to various security threats risk. Secure cloud infrastructure is the primary task for improvement on cloud security. Intrusion detection is a kind of passive defense technology, which is good at real-time recognition of known attack patterns, but it’s not skillful in detecting unknown attack patterns. Honeypot is a kind of active defense technology, which provides fake information, system or network environment, alluring the attackers to conduct attacks, then analysis of attack patterns and appropriate reactions could be performed. This paper introduces a scheme for incorporating intrusion detection and honeypot technologies into cloud infrastructure Eucalyptus, which augments the cloud service security and reliability.