Abstract:To solve the problems of relationship between efficiency and security in traditional WWW intrusion tolerant system
a multilevel intrusion toleration mechanism was proposed. First
each web document had corresponding security level which was classified by its size and sensitivity. The initial grading factor was specified and dynamically adjusted by the security risks of web documents. Additionally
by the coefficient of Logistic equation
the uncertainty and initial value sensitivity of chaotic system was used to generate the chaotic fragment and its signature according to the initial grading factor. Even if the integrity of the web documnet requested by user was destroyed
the mechanism can also trigger a series of intrusion toleration oprarions include detecting the intrusion
denying the invalid access
alerting and renewing the system
etc. Because the chaotic intial value was produced randomly and chaotic system had character of initial value sensitivity
the chaotic fragment according to the chaotic intial value was uncertain. The invader was difficult to forged the signature of the chaotic fragment. The experiments showed that the security mechanism can carry a better balance between security and efficiency.
关键词
容侵混沌摘要签名
Keywords
intrusion tolerantchaosdigestsignature
references
Johnson D M,Williams D,Organically assured and survivable information system[Technical Report DARPA/ITO],2001.
Stroud R,Welch I,Warne J,A qualitative analysis of the intrusion-tolerance capabilities of the MAFTIA architecture,2004.
Stroud R,Welch I,Warne J,A qualitative analysis of the intrusion-tolerance capabilities of the MAFTIA architecture,2004.
Verissimo P E,Neves N F,Correia M P,Intrusion-tolerant architectures:Concepts and design[Technical Report DI/FCUL TR03-5],2003.
Stavridou V,Dutertre B,Riemenschneider R A,Intrusion tolerant software architectures,2001.
Rathi M,Anjum F,Zbib R,Investigation of intrusion tolerance for COTS middleware,2002.
Amoroso E G,Intrusion detection:An introduction to internet surveillance,correlation,trace back,traps,and response intrusion,Net Books,1999.
Huang Zunguo.Lu Xicheng.Wang Huaimin
Goseva-Popstojanova K,Wang Feiyi,Wang Rong,Characterizing intrusion tolerant systems using a state transition model,DISCEX,2001.
Devaney,An introduction to chaotic dynamical system,Addison-Wesley Publishing Company,Inc,1989.
王相生.甘骏人 一种基于混沌的序列密码生成方法 [J].
Zhang Jianhua,Li Tao,An immune evolutionary algorithm based on chaos mutation,2006.