In a ubiquitous environment, the hardware resources are limited; thus, an appropriate resource management mechanism is required for guaranteeing its processing activity. However, most operating systems (OSs) lack an access control mechanism for CPU resources to guarantee satisfactory processing and to safeguard the system from malicious attacks that affect the CPU resources, resulting in denial of service (DoS). Access control is not intended for CPU resources, which are important for the execution of a program. As a result, OSs cannot control the usage ratio of CPU resources. In this paper, we propose an access control model for CPU resources based on an execution resource. The proposed model can control the usage ratio of CPU resources appropriately for each user and each program domain. This execution resource can be applied to mitigate DoS attacks. In order to evaluate the effectiveness of the proposed method, we describe the results of a basic performance experiment and a DoS simulation experiment employing the Apache web server. From the results, we show that the proposed method can mitigate DoS attacks and does not have bad effects upon the performance of a target service.
목차
Abstract 1. Introduction 2. Related Work 3. Execution Resource 3.1. Overview 3.2. Types of Execution Resources 3.3. Hierarchical Execution Tree 3.4. Operation Interface of Execution Resource 4. Execution Resource with Upper Bound 4.1. Mechanism of Rate Limiting Using Execution Resources 4.2. Advantages 5. Execution-Resource-Based Access Control Model for CPU Resource 5.1. Access Control of Execution Resource 5.2. Mapping Model of Execution Resource 6. Implementation 6.1. Tender Operating System 6.2. Implementation of Execution Resource with Upper Bound 7. Evaluation 7.1. Purpose of experiments 7.2. Basic performance evaluation 7.3. DoS attack simulation against the Apache Web server 7.4. Evaluation of performance regulation 8. Conclusion 9. References
저자
Toshihiro Tabata [ Graduate School of Natural Science and Technology, Okayama University ]
Satoshi Hakomori [ Graduate School of Natural Science and Technology, Okayama University NTT DATA Corporation ]
Kazutoshi Yokoyama [ NTT DATA Corporation ]
Hideo Taniguchi [ Graduate School of Natural Science and Technology, Okayama University ]
보안공학연구지원센터(IJSH) [Science & Engineering Research Support Center, Republic of Korea(IJSH)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Smart Home
간기
격월간
pISSN
1975-4094
수록기간
2008~2016
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Smart Home Vol.1 No.2