Towards Cyber Resiliency in the Context of Cloud Computing

Towards Cyber Resiliency in the Context of Cloud Computing
复制标题

云计算背景下的网络弹性

DOI:
--
复制
发表时间:
2018
期刊:
IEEE S&P 2018
影响因子:
--
通讯作者:
A. Singhal
A. Singhal
中科院分区:
--
文献类型:
--
作者:
Xiaoyan Sun;Peng Liu;A. Singhal

文献摘要

被引文献

相似文献

网络弹性是企业网络在攻击活动中持续提供(支持的任务和业务流程)基本功能的能力。它被定义为“对包含网络资源的系统进行预测、承受、恢复和适应不利条件、压力、攻击或妥协的能力”[1]。从概念上讲,能力可以通过所支持的任务和业务流程是否能够成功来衡量,尽管攻击活动造成了各种影响。由于不同任务和业务流程的成功标准通常不同,因此网络弹性通常是一个相对的概念。使业务流程 A 在攻击活动中取得成功并不意味着企业网络的网络弹性能力也将使业务流程 B 在同一攻击活动中取得成功。尽管从技术上讲,可以在操作系统级别或网络服务级别定义非相对的系统范围网络弹性标准,但在许多情况下,此类网络弹性测量并不能直接测量业务方网络弹性(例如,任务受攻击活动影响的程度)。
Cyber resiliency is the capability of an enterprise network to continuously provide (the supported missions and business processes with) essential functions in the midst of an attack campaign. It is defined as “the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that include cyber resources” [1]. Conceptually speaking, the capability can be measured by whether the supported missions and business processes can succeed in spite of the various impact being caused by the attack campaign. Since the success criteria for different missions and business processes are often different, cyber resiliency is in general a relative notion. Enabling business process A to succeed in the midst of an attack campaign does not really mean that the enterprise network’s cyber resiliency capability will also enable business process B to succeed in the midst of the same attack campaign. Although technically it is possible to define non-relative system-wide cyber resiliency criteria at the operating system level or the network service level, such cyber resiliency measurements in many cases do not directly measure the business side cyber resiliency (e.g., to which extent a task is affected by the attack campaign).