首页> 外文期刊>Journal of network and computer applications >A cyber-resilient architecture for critical security services
【24h】

A cyber-resilient architecture for critical security services

机译:关键安全服务的网络弹性架构

获取原文
获取原文并翻译 | 示例
           

摘要

Authentication and authorization are two of the most important services for any IT infrastructure. Taking into account the current state of affairs of cyber warfare, the security and dependability of such services is a first class priority. For instance, the correct and continuous operation of identity providers (e.g., OpenID) and authentication, authorization and accounting services (e.g., RADIUS) is essential for all sorts of systems and infrastructures. As a step towards this direction, we introduce a functional architecture and system design artifacts for prototyping fault- and intrusion-tolerant identification and authentication services. The feasibility and applicability of the proposed elements are evaluated through two distinct prototypes. Our findings indicate that building and deploying resilient and reliable critical services is an achievable goal through a set of system design artifacts based on well-established concepts in the fields of security and dependability. Additionally, we provide an extensive evaluation of both resilient RADIUS (R-RADIUS) and OpenID (R-OpenID) prototypes. We show that our solution makes services resilient against attacks without affecting their correct operation. Our results also pinpoint that the prototypes are capable of meeting the needs of small to large-scale systems (e.g., IT infrastructures with 800k to 10M users). (C) 2016 Elsevier Ltd. All rights reserved.
机译:身份验证和授权是任何IT基础架构最重要的两项服务。考虑到网络战的当前状况,此类服务的安全性和可靠性是头等大事。例如,身份提供者(例如,OpenID)以及认证,授权和计费服务(例如,RADIUS)的正确和连续的运行对于各种系统和基础设施都是必不可少的。作为朝这个方向迈出的一步,我们介绍了一种用于对容错和入侵容忍的标识和认证服务进行原型设计的功能体系结构和系统设计工件。通过两个不同的原型评估了拟议要素的可行性和适用性。我们的发现表明,通过基于安全性和可靠性领域中公认的概念的一组系统设计工件,构建和部署有弹性且可靠的关键服务是可以实现的目标。此外,我们对弹性RADIUS(R-RADIUS)和OpenID(R-OpenID)原型提供了广泛的评估。我们证明了我们的解决方案使服务具有抵御攻击的能力,而不会影响其正确的操作。我们的结果还明确指出,原型能够满足小型到大型系统的需求(例如,拥有80万至1000万用户的IT基础架构)。 (C)2016 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号