Til hovedinnhold
Norsk English

Service Injection: A Threat to Self-managed Complex Systems

Sammendrag

Abstract—The promises of a service-centric Future Internet, where we can mix, match and create rapid-grown services also bring new security challenges. This paper investigates a threat named service injection to self-managed composite service systems that consist of service components from different providers. The overall goal of service injection is to have a malicious service component become a part of a composite service.This can be done by provoking a runtime recomposition and taking the place of a legitimate service component. Service injection could quickly become as prevalent as today’s widespread code injection, it is being held back by the fact that there are not many system configurations in which it may manifest itself. However, with the emerging trends of autonomic and heterogenous system-of-systems, we should start to think about precautions before it is too late. In order to analyze and classify service injection we have used the CAPEC schema for standard attacks.

Kategori

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel

Språk

Engelsk

Forfatter(e)

Institusjon(er)

  • SINTEF Digital / Software Engineering, Safety and Security

År

2012

Forlag

IEEE conference proceedings

Bok

2011 Ninth International Conference on Dependable, Autonomic and Secure Computing (DASC) : Sydney 12-14 Dec. 2011

ISBN

978-1-4673-0006-3

Vis denne publikasjonen hos Cristin