计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (18): 98-102.

• 网络、通信、安全 • 上一篇    下一篇

大规模分布式系统实体交互脆弱性分析方法

赵 刚1,2,赵金晶2,况晓辉2,郑纬民1   

  1. 1.清华大学 计算机科学与技术系,北京 100084
    2.北京系统工程研究所,北京 100101
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-06-21 发布日期:2011-06-21

Analysis on entity interaction vulnerability in large-scale distributed system

ZHAO Gang1,2,ZHAO Jinjing2,KUANG Xiaohui2,ZHENG Weimin1   

  1. 1.Department of Computer Science and Technology,Tsinghua University,Beijing 100084,China
    2.Beijing Institute of System Engineering,Beijing 100101,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-06-21 Published:2011-06-21

摘要: 大规模分布式系统中资源、用户、计算和管理分布化的特点,决定了实体间的频繁交互成为大规模分布式系统完成基本业务和实现安全机制的基本手段。针对因安全机制缺失而引入的大规模分布式系统交互脆弱性问题,提出了一种大规模分布式系统实体交互脆弱性分析模型LDS-IVA;通过对大规模分布式系统实体交互过程进行建模,采用可通用的大规模分布式系统交互安全机制描述语言IS-LAN描述各实体的安全机制,以大规模分布式系统中的关键资源为分析对象,采用有限状态机的方法对大规模分布式系统实体交互进行分析和验证,发现安全机制缺失和不足对关键资源机密性、完整性和可用性的影响,以识别大规模分布式系统交互中存在的脆弱性及其可能引发的攻击模式。

关键词: 大规模分布式系统, 实体交互模型, 脆弱性分析, 有限状态机

Abstract: Due to the resource distributing,user distributing,computing distributing and management distributing in Large-scale Distributed System(LDS),the frequent interaction between entities becomes the foundation for the implementation of its basic operation and security mechanism.An analysis model named as LDS-IVA on Interaction Vulnerability Analysis is presented,which is aimed at the analysis of entity interaction vulnerabilities resulting from the lack of security mechanism.LDS-IVA builds the entity interaction model,designs the general interaction security mechanism description language IS-LAN,takes the key resources in LDS as the objects for analyzing,and adopts the Finite State Machine(FSM) technique to analyze and validate the entity interaction vulnerabilities.In this way,LDS-IVA finds out the bad influence on the resource confidentiality,integrity and availability caused by the lack of security mechanism,and thus recognizes the vulnerabilities and attack patterns in LDS.

Key words: Large-scale Distributed System(LDS), entity interaction model, vulnerability analysis, Finite State Machine(SFM)