科技报告详细信息
Towards Diversity of COTS Software Applications: Reducing Risks of Widespread
Casassa Mont, Marco ; Baldwin, Adrian ; Beres, Yolanta ; Harrison, Keith ; Sadler, Martin ; Shiu, Simon
HP Development Company
关键词: COTS applications;    diversity;    faults;    attacks;    survivability;    security;    trust;   
RP-ID  :  HPL-2002-178
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

Recent IT attacks demonstrated how vulnerable consumers and enterprises are when adopting commercial and widely deployed operating systems, software applications and solutions. Diversity in software applications is fundamental to increase chances of survivability to faults and attacks. Current approaches to diversity are mainly based on the development of multiple versions of the same software, their parallel execution and the usage of voting mechanisms. Because of the high cost, they are used mainly for very critical and special cases. We introduce and discuss an alternative method to ensure diversity for common, widespread software applications without requiring additional computational resources. This method takes advantage of the componentisation of modern software solutions and enforces diversity at the installation time, by a random selection and deployment of critical software components. Randomisation criteria are adaptable to feedback gathered from software installations and affect software components' lifecycle. We describe a few encouraging results obtained from simulations. 15 Pages

【 预 览 】
附件列表
Files Size Format View
RO201804100001771LZ 74KB PDF download
  文献评价指标  
  下载次数:19次 浏览次数:39次