首页> 外文会议>Annual IEEE-IFIP International Conference on Dependable Systems and Networks-Supplemental Volume >Design and Performance Analysis of Software Defined Networking Based Web Services Adopting Moving Target Defense
【24h】

Design and Performance Analysis of Software Defined Networking Based Web Services Adopting Moving Target Defense

机译:基于软件定义网络的移动目标防御Web服务设计与性能分析

获取原文

摘要

Moving Target Defense (MTD) has been emerged as a promising countermeasure to defend systems against cyberattacks asymmetrically while working well with legacy security and defense mechanisms. MTD provides proactive security services by dynamically altering attack surfaces and increasing attack cost or complexity to prevent further escalation of the attack. However, one of the non-trivial hurdles in deploying MTD techniques is how to handle potential performance degradation (e.g., interruptions of service availability) and maintain acceptable quality-of-service (QoS) in an MTD-enabled system. In this paper, we derive the service performance metrics (e.g., an extent of failed jobs) to measure how much performance degradation is introduced due to MTD operations, and propose QoS-aware service strategies (i.e., drop and wait) to manage ongoing jobs with the minimum performance degradation even under MTD operations running. We evaluate the service performance of software-defined networking (SDN)-based web services (i.e., Apache web servers). Our experimental results prove that the MTD-enabled system can minimize performance degradation by using the proposed job management strategies. The proposed strategies aim to optimize a specific service configuration (e.g., types of jobs and request rates) and effectively minimize the adverse impact of deploying MTD in the system with acceptable QoS while retaining the security effect of IP shuffling-based MTD.
机译:移动目标防御(MTD)已经成为一种有前途的对策,可以在与传统安全和防御机制很好地配合的同时,不对称地防御系统的网络攻击。 MTD通过动态更改攻击面并增加攻击成本或复杂性来防止攻击进一步升级,从而提供主动安全服务。然而,部署MTD技术的一个不小的障碍是如何处理潜在的性能下降(例如,服务可用性的中断)以及如何在启用了MTD的系统中维持可接受的服务质量(QoS)。在本文中,我们导出服务性能指标(例如,失败作业的程度)以衡量由于MTD操作而导致的性能下降,并提出QoS感知服务策略(即,丢弃和等待)来管理正在进行的作业即使在运行MTD的情况下,性能下降也最小。我们评估基于软件定义网络(SDN)的Web服务(即Apache Web服务器)的服务性能。我们的实验结果证明,使用建议的作业管理策略,支持MTD的系统可以最大程度地降低性能下降。所提出的策略旨在优化特定的服务配置(例如,作业类型和请求速率),并有效地最小化在可接受的QoS中在系统中部署MTD的不利影响,同时保留基于IP改组的MTD的安全效果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号