项目名称: 面向虚拟计算环境的入侵容忍机制研究
项目编号: No.60803114
项目类型: 青年科学基金项目
立项/批准年度: 2009
项目学科: 交通运输
项目作者: 赵峰
作者单位: 华中科技大学
项目金额: 20万元
中文摘要: 基于虚拟机的虚拟计算环境已逐步成为航空、航天、金融、军事、交通、政务等国家重要领域的新兴计算平台。然而随着计算环境虚拟化的迅速普及,针对虚拟计算环境的恶意攻击事件日益增多,潜在安全隐患防不胜防,因此,如何容忍入侵就成为虚拟计算环境中一项迫切而富有挑战性的研究课题。本项目针对虚拟计算环境开放性、一体性、复杂性和动态性的特点,研究面向虚拟计算环境的入侵容忍机制。项目具体研究内容包括:虚拟计算环境入侵行为动态演化规律的描述及虚拟计算环境故障表现模型的构建、虚拟计算环境入侵企图预测和入侵行为的实时检测、虚拟计算环境下的入侵容忍决策、虚拟计算环境多阶进化的数据与系统服务的入侵容忍机制设计。此外,本项目还将利用Xen 等开源虚拟机软件仿真虚拟计算环境验证提出的容侵机制。本项研究工作具有重要的理论价值和现实意义,研究成果将为创建安全的虚拟计算环境奠定基础,及丰富入侵容忍、虚拟计算与数据挖掘领域的研究内容。
中文关键词: 虚拟计算;入侵容忍;入侵企图;决策
英文摘要: VM-based virtual computing environment has gradually become emerging computing platform in national important areas, such as aviation, aerospace, financial, military, transportation, government and other important areas. However, with the rapid adoption of computing virtualization, malicious attacks for vitual computing environment increase greatly, which is hard to detect potential security risk. Therefore, how to tolerate the intrusion in virtual computing environment becomes an urgent and challengingresearch topic. Facing open, integrated, complex and dynamic characteristics of virtual computing environment, porject focuses on the intrusion tolerance mechanisms. Specific researches of this project include: dynamic evolution and fault model of virtual computing environment, intrusion attempts prediction and real-time intrusion detection in virtual computing environment, intrusion tolerant decision in virtual computing environment, mechanism on data and multi-stage evolution of intrusion tolerant system service. In addition, the project will use open-source Xen software to simulate virtual computing environment and verify proposed mechanism of intrusion tolerance. This study has important theoretical and practical significance. Research results will create a secure basis for virtual computing environment, and also shuld rich the contents of intrusion tolerance, virtual computing and data mining.
英文关键词: Virtual Computing; Intrusion Tolerance; Intrusion Purpose; Decision