Mimic web application security technology based on DHR architecture
Dan Wei, Xiao Min Liang, Shi Lin, Linlin Yu · International Conference on Artificial Intelligence and Intelligent Information Processing (AIIIP 2022) · 2022
Traditional static defense methods based on threat detection, isolation and filtering are difficult to defend against increasingly complex and intelligent cloud network intrusions. New defense methods try to increase the uncertainty and complexity of the cloud environment. Aiming at the problems of increasing attack surface of web services and difficult security management and control, based on the mimetic web endogenous security system architecture, this paper presents the system physical frame and logical frame of Mimicloud, a web architecture of the DHR model based on the continuous time Markov chain Model and analyze the security mechanism, and finally conduct an evaluation test. This paper innovatively uses the DHR cloud endogenous security architecture to provide highly secure SaaS services, and then constructs a security mechanism with dynamic, random, diversity and other characteristics, which makes the attacker lose part of the latent resources and attack implementation conditions. It is difficult to maintain the continuous control and access to the successful attack. The mimic Web can also provide theoretical support for enhancing the endogenous security capabilities of the next-generation information cloud infrastructure and key technological breakthroughs of mimic security defense in the cloud environment.