A Model of Attacks of Malicious Hosts Against Mobile Agents

A Model of Attacks of Malicious Hosts Against Mobile Agents
复制标题

恶意主机针对移动代理的攻击模型

DOI:
10.1007/3-540-49255-0_77
复制
发表时间:
1998
期刊:
ECOOP Workshops
影响因子:
--
通讯作者:
F. Hohl
F. Hohl
中科院分区:
--
文献类型:
--
作者:
F. Hohl

文献摘要

被引文献

相似文献

移动的代理和其他移动的代码实体通过程序在通常不由该程序的雇主维护的计算机上执行的可能性来扩展(静止的)分布式系统的潜力。在这种情况下,两方参与运行一个程序,因此必须保证一方不会伤害另一方。特别是,即使在适度的应用程序中,以及在电子商务领域的应用程序中,也存在移动的代理必须被保护以免受执行方或主机的攻击的方面。此外,这个问题被认为是非常困难的,因为目前只有两种方法试图完全解决这个问题。另一个困难,在寻找一个解决这个问题,是-相反的一些其他系统机制的移动的代理-这是不够的,只是提出一个机制,似乎解决了这个问题,但一个正式的证明必须给出的解决方案。因此,本文提出了一个模型的攻击,可用于恶意主机对移动的代理。该模型旨在成为对单一攻击和潜在保护机制强度进行形式化分析的基础,为此,提出了一组对该模型的要求。使用现有的机器模型,即随机存取存储程序加堆栈机器(或RASPS),攻击模型,满足这些要求的描述。在这个模型中,执行过程的组件可以从外部访问。这一事实被执行攻击程序的另一台机器用来控制代理程序的执行。攻击模型可用于两个主要目的。第一个目的是演示恶意主机的问题。与例如数据加密问题相反,移动的代理不仅受到主机的单个攻击,而且受到主机的一整套可能的攻击,并且目前甚至不清楚是否已经识别出所有这些攻击。攻击模型可用于编写尝试执行某种攻击的攻击程序。该模型的第二个目的是提供一个基础,证明强度的保护方案的算法,试图保护代理免受恶意主机。指出保护算法不仅要安全,而且其产生的代码也必须受到保护。全文可通过URL访问 http://www.informatik.uni-stuttgart.de/ipvr/vs/projekte/mole/simc98.ps.gz .
Mobile agents and other mobile code entities extend the potential of (stationary) distributed systems by the possibility of programs being executed at computers that are often not maintained by the employer of that program. Here two parties are involved in running a program, and thus guarantees have to be given that one party will not harm the other. Especially the aspect that a mobile agent has to be protected against attacks of the executing party, orhost, exists even in modest applications, and in those of the the electronic commerce domain. Furthermore, this problem is regarded to be very difficult as there are currently only two approaches that try to solve this problem entirely. Another difficulty in finding a solution for this problem, is that - contrary to some other system mechanisms for mobile agents - it is not enough to just propose a mechanism that seems to solve the problem, but a formal proof has to be given that the solution holds. The paper therefore proposes a model of attacks that can be used by malicious hosts against mobile agents. It is intended to be the basis for a formal analysis of single attacks and of the strength of potential protection mechanisms.For that purpose, a set of requirements for such a model is presented. Using an existing machine model, namely Random Access Stored Program plus Stack machines (or RASPS), an attack model that fulfils these requirements is described. In this model, the components of the execution process can be accessed from outside. This fact is used by another machine that executes an attack program to control the execution of an agent program. The attack model can be used for two main purposes. The first purpose is the demonstration of the problem of malicious hosts. Contrary to e.g. data encryption problems, mobile agents are subject not only to a single, but a whole set of possible attacks by the host and it is currently not even clear whether all of these attacks are already identified. The attack model can be used to write an attack program that tries to perform a certain attack. The second purpose of the model is to offer a basis for proving the strength of the protection scheme of algorithms that try to protect agents from malicious hosts. It is pointed out that not only a protection algorithm needs to be secure but also the code it produces must be protected. The full paper can be accessed using the URL http://www.informatik.uni-stuttgart.de/ipvr/vs/projekte/mole/simc98.ps.gz .