错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cyber Attack Victim Separation: New Dimensions to Minimize Attack Effects by Resource Management

  • Anmol Kumar,
  • Gaurav Somani

摘要

There are numerous cyber attacks that take place every year in the cloud computing environment. Few common cyber attacks include denial of service (DOS) attacks, phishing attacks, SQL injection attacks, ransomware attacks, and many other malware driven attacks. During the presence of cyber-attacks, the information security teams of the victim organization should always strive to minimize the attack effects by limiting the attack to affect minimum number of services, servers, networks, and customers. Cyber attacks may spread quickly in the cloud environment because of shared resources and network. One obvious method is to separate or isolate the affected victim service or machine from the rest of the services or the network. There may be other methods which may always try to hide the victim service from the direct contact by the attackers. This may include methods such as using load-balancers or moving target defense (MTD) driven methods. We see a heavy use of resource sharing in multi-tenant environments such as cloud infrastructures. Not having proper resource isolation may also result into collateral damages among the multi-tenant services in cloud based deployments. Resource containment, migration, and victim separation are some of the methods which may help in managing resources of cloud infrastructure during the attack presence. In this chapter, we discuss a new area of cyber attack management which we denote as ‘victim separation’, where we collate important methods helping in victim service separation and isolation to minimize the attacks effects. For this, we include contributions from the areas such as resource isolation, moving target defense (MTD), migration, demilitarized zone, and solutions to co-residency attacks. We also provide a discussion and future directions related to the area of victim separation.