通信学报 ›› 2018, Vol. 39 ›› Issue (4): 176-188.doi: 10.11959/j.issn.1000-436x.2018069

• 学术通信 • 上一篇    下一篇

APM:适用于IaaS平台的agent保护机制

樊佩茹,赵波,倪明涛,陈治宏   

  1. 武汉大学国家网络安全学院空天信息安全与可信计算教育部重点实验室,湖北 武汉430072
  • 出版日期:2018-04-01 发布日期:2018-04-29
  • 作者简介:樊佩茹(1990-),女,山西忻州人,武汉大学博士生,主要研究方向为虚拟化与云安全。|赵波(1972-),男,山东青岛人,武汉大学教授、博士生导师,主要研究方向为可信计算、虚拟化安全、嵌入式系统安全等。|倪明涛(1977-),男,湖北天门人,武汉大学博士生,主要研究方向为可信计算、物联网安全等。|陈治宏(1984-),女,重庆人,武汉大学博士生,主要研究方向为虚拟化与云存储安全。
  • 基金资助:
    国家高技术研究发展计划(“863”计划)基金资助项目(2015AA016002);国家重点基础研究发展计划(“973”计划)基金资助项目(2014CB340600)

APM:agent protection mechanism applied for IaaS platform

Peiru FAN,Bo ZHAO,Mingtao NI,Zhihong CHEN   

  1. Key Laboratory of Aerospace Information Security and Trusted Computing Ministry of Education,School of Computer Science/School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,China
  • Online:2018-04-01 Published:2018-04-29
  • Supported by:
    The National High Technology Research and Development Program of China (863 Program)(2015AA016002);The National Basic Research Program of China (973 Program)(2014CB340600)

摘要:

在IaaS平台中,虚假数据的存在将对测评结果造成混淆,无法为用户给出公平公正的平台选择依据。针对该问题,提出一种适用于IaaS平台的测试代理agent保护机制(APM,agent protection mechanism),在不需要额外软硬件支持的条件下保证agent的完整性和命令执行的正确性;同时提出一种基于质询的APM有效性验证方法,及时发现失效APM所在IaaS节点以止损。实现了基于APM的实验环境,对APM的有效性和性能开销进行测试。实验结果表明,该机制可以有效保护agent的完整性及其执行命令的正确性,且对IaaS平台引入的性能代价较小。

关键词: IaaS平台, 测试, 代理, 度量

Abstract:

The interference of false or fake test data on IaaS platform will contaminate the evaluation results,confusing users’ choices for IaaS services.To solve this problem,an agent protection mechanism (APM) for IaaS platform test environment was proposed.It ensured the integrity and commanded validity of the agent without additional hardware or software.Also an effectiveness verification approach based on requests was presented to detect APM failure problems timely.An experiment environment according to APM was implemented to evaluate the effectiveness and the performance overhead.Experimental results show that the APM is effective in protecting agent integrity and command validation,and its performance overhead is minor.

Key words: IaaS platform, test, agent, measurement

中图分类号: 

No Suggested Reading articles found!