Towards Scalable Defense of Information Flow Security for Distributed Systems

被引:1
作者
Fu, Xiaoqin [1 ]
机构
[1] Washington State Univ, Pullman, WA 99164 USA
来源
PROCEEDINGS OF THE 28TH ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS (ISSTA '19) | 2019年
关键词
Information flow; Security; Scalability; Distributed system;
D O I
10.1145/3293882.3338988
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
It is particularly challenging to defend common distributed systems against security vulnerabilities because of the complexity and their large sizes. However, traditional solutions, that attack the information flow security problem, often fail for large, complex real-world distributed systems due to scalability problems. The problem would be even exacerbated for the online defense of continuously-running systems. My proposed research consists of three connected themes. First, I have developed metrics to help users understand and analyze the security characteristics of distributed systems at runtime in relation to their coupling measures. Then, I have also developed a highly scalable, cost-effective dynamic information flow analysis approach for distributed systems. It can detect implicit dependencies and find real security vulnerabilities in industrial distributed systems with practical portability and scalability. In order to thoroughly solve the scalability problem in general scenarios, I am developing a self-adaptive dynamic dependency analysis framework to monitor security issues during continuous running. In this proposal, I outline the three projects in a related manner as to how they consistently target the central objective of my thesis research.
引用
收藏
页码:438 / 442
页数:5
相关论文
共 20 条
[1]  
[Anonymous], 2011, NDSS
[2]   Dynamic coupling measurement for object-oriented software [J].
Arisholm, E ;
Briand, LC ;
Foyen, A .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2004, 30 (08) :491-506
[3]  
Austin Thomas H, 2010, P 5 ACM SIGPLAN WORK, V3
[4]  
Cai H., 2014, ASE 2014 P 29 ACMIEE, P343
[5]   DistIA: A Cost-Effective Dynamic Impact Analysis for Distributed Programs [J].
Cai, Haipeng ;
Thain, Douglas .
2016 31ST IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE), 2016, :344-355
[6]  
Cai Haipeng, 2016, ARXIV160404638
[7]  
Coulouris G., 2011, Distributed Systems: Concepts and Design, V5th
[8]  
de Lemos R., 2013, LNCS, V7475, P1, DOI [DOI 10.1007/978-3-642-35813-5_1, 10.1007/978-3-642-35813-51, DOI 10.1007/978-3-642-35813-51]
[9]   A journey to highly dynamic, self-adaptive service-based applications [J].
Di Nitto, Elisabetta ;
Ghezzi, Carlo ;
Metzger, Andreas ;
Papazoglou, Mike ;
Pohl, Klaus .
AUTOMATED SOFTWARE ENGINEERING, 2008, 15 (3-4) :313-341
[10]   TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones [J].
Enck, William ;
Gilbert, Peter ;
Han, Seungyeop ;
Tendulkar, Vasant ;
Chun, Byung-Gon ;
Cox, Landon P. ;
Jung, Jaeyeon ;
McDaniel, Patrick ;
Sheth, Anmol N. .
ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2014, 32 (02)