摘要
分析了入侵与故障的区别,指出在安全领域直接使用容错方法存在模型上的不可行性。提出了一种面向特定服务的入侵容忍方法。这种方法关注的是入侵的结果而不是入侵本身,即在保证系统功能连续的情况下,利用门限密码以及大数表决等技术检测入侵的存在,然后用容错技术重构和恢复受攻击的系统。详细介绍了这种面向特定服务的入侵容忍方法的信任模型,讨论了系统的初步实现。
It is infeaseible to apply fault-tolerant directly in the security tolerant-specific services-oriented method is presented. It can integrate the fa paradigm. A novel methord of intrusion uh tolerant into security paradigm. The traditional fault tolerant method focuses on the causes and existence of fault, and so can deal with unknown intrusion. In this method, both verifiable secret sharing and major voting are used to detect the effects of intrusion and fault-tolerant approaches. Its model and architecture are presented and some further research directions are introduced.
出处
《科学技术与工程》
2009年第4期1047-1050,共4页
Science Technology and Engineering
关键词
面向服务
入侵容忍
系统失效
services-oriented intrusion-tolerant systems failure