Using Diversity in Cloud-Based Deployment Environment to Avoid Intrusions

  1. Lookup NU author(s)
  2. Dr Anatoliy Gorbenko
  3. Professor Alexander Romanovsky
Author(s)Romanovsky A; Gorbenko A; Kharchenko V; Tarasyuk O
Publication type Report
Series TitleSchool of Computing Science Technical Report Series
Legacy DateJuly 2011
Report Number1262
Full text is available for this publication:
This paper puts forward a generic intrusion-avoidance architecture to be used for deploying web services on the cloud. The architecture, targeting the IaaS cloud providers, avoids intrusions by employing software diversity at various system levels and dynamically reconfiguring the cloud deployment environment. The paper studies intrusions caused by vulnerabilities of system software and discusses an approach allowing the system architects to decrease the risk of intrusions. This solution will also reduce the so-called system’s days-of-risk which is calculated as a time period of an increased security risk between the time when a vulnerability is publicly disclosed to the time when a patch is available to fix it.
InstitutionSchool of Computing Science, University of Newcastle upon Tyne
Place PublishedNewcastle upon Tyne
ActionsLink to this publication