计算机工程与应用 ›› 2008, Vol. 44 ›› Issue (15): 15-17.

• 博士论坛 • 上一篇    下一篇

一种新型多层可生存信息服务架构

陈海涛,卢宇彤,黄遵国   

  1. 国防科技大学 计算机学院,长沙 410073
  • 收稿日期:2007-12-28 修回日期:2008-03-03 出版日期:2008-05-21 发布日期:2008-05-21
  • 通讯作者: 陈海涛

Multilayer survivable architecture for information service

CHEN Hai-tao,LU Yu-tong,HUANG Zun-guo   

  1. College of Computer,National University of Defense Technology,Changsha 410073,China
  • Received:2007-12-28 Revised:2008-03-03 Online:2008-05-21 Published:2008-05-21
  • Contact: CHEN Hai-tao

摘要: 针对分布信息系统面临的安全威胁,综合P2P网络的无集中控制、漂移、共享等特性,虚拟化技术的共存、隔离、异构等特性提出一种新型多层可生存信息服务结构-CUIRASS,有效提高了部件失效和被入侵状态下持续服务的能力。该架构应用多样化服务群破坏黑客入侵传播过程,并利用虚拟化技术克服多样化服务的部署难题;采用基于定制的服务代理节点和服务代理节点协同实现分布拒绝服务攻击的抵御;构造服务代理层实现安全相关信息的过滤和覆盖网路由,有效隐藏服务节点信息,破坏黑客信息收集过程;提出综合多种漂移方式的动态可生存服务模式,利用虚拟化实现服务的重配置、快速备份和恢复,克服传统的主备模式和集群模式存在的开销大和实时性差的问题。

关键词: 生存性, 信息系统, 多层, P2P, 虚拟化

Abstract: A new multilayer survivable architecture-CUIRASS which has continuous service ability under malfunction and intrusion situation is proposed in this paper.The architecture combines the decentralized control,service excursion and resource sharing ability of peer-to-peer overlay with the coexistence,isolation,heterogeneity ability of visualization technology to improve the survivability of information service.It applies diverse service pools to destroy the propagation of intrusion and uses visualization technology to solve the deployment problem.It defenses the DDoS attack by using customized broker nodes and enabling collaboration of broker nodes.It hides info of service nodes and destroys the attacker process of collecting information by constructing service broker layer to filter security-related information and implement overlay network routing.A dynamic survivable service mode is proposed to combine multi excursion method and use visualization to reconfigure,backup and recovery services which solve the problem of large consumption and bad real time of traditional active/backup mode and cluster mode.

Key words: survivability, information system, multilayer, peer-to-peer, visualization