Cyber attacks are becoming more frequent and sophisticated, introducing significant challenges for organizations to protect their systems and data from threat actors. Today, threat actors are highly motivated, persistent, and well-founded and operate in a coordinated manner to commit a diversity of attacks using various sophisticated tactics, techniques, and procedures. Given the risks these threats present, it has become clear that organizations need to collaborate and share cyber threat information (CTI) and use it to improve their security posture. In this paper, we present TRADE – TRusted Anonymous Data Exchange – a collaborative, distributed, trusted, and anonymized CTI sharing platform based on blockchain technology. TRADE uses a blockchain-based access control framework designed to provide essential features and requirements to incentivize and encourage organizations to share threat intelligence information. In TRADE, organizations can fully control their data by defining sharing policies enforced by smart contracts used to control and manage CTI sharing in the network. TRADE allows organizations to preserve their anonymity while keeping organizations fully accountable for their action in the network. Finally, TRADE can be easily integrated within existing threat intelligence exchange protocols such as trusted automated exchange of intelligence information (TAXII) and OpenDXL, thereby allowing a fast and smooth technology adaptation.
With the ever-growing volume of cyber-attacks on organizations, security analysts require effective visual interfaces and interaction techniques to detect security breaches and, equally importantly, to efficiently share threat information. To support this need, we present a tool called ?User Behavior Analytics? (UBA) that conducts continuous analysis of individuals' usage of their organizational IT networks, and effectively visualizes the associated security exposures of the organization. The UBA tool was developed as an extension of IBM?s security analytics environment, and incorporates a risk-focused dashboard that highlights anomalous user behaviors and the aggregated risk levels associated with individual users, user groups, and overall system security state. Moreover, the tool?s dashboard has been designed to facilitate rapid review of security incidents and correlate them with data from various sources such as user directory and HR systems. In doing so, the tool presents busy security analysts with an effective means to visually identify and respond to cyber threats on the organization's crown jewels.
The future internet is evolving as an internet of services, things and infrastructure, and the European Commission is supporting research projects that are contributing to its evolution. Among the others, RESERVOIR, VISION Cloud and CloudWave are three interesting examples of how infrastructures and data can be managed in an effective way and how applications can adapt to the infrastructure, and the infrastructure to the services requested, in order to improve the overall quality of the service provided. From our experience in these three successful projects, we show in this paper how they try to address the challenges described above, providing an important boost to making the future internet vision concrete. We also discuss our view of the future internet where sensors, actuators and objects are part of the cloud.
The Future Internet is required to be fast, flexible and ever-responsive to demands from both humans and machines. It is evolving as an Internet of services, things, and infrastructure and the European Commission is supporting research projects that are contributing to its evolution. Among the others, VISION Cloud and Cloudwave are two interesting examples of how data can be managed in an effective way and how applications can adapt to the infrastructure, and the infrastructure to the services requested, in order to improve the overall quality of the service provided. From our experience in these two successful projects, we show in this paper how they try to address the challenges described above, providing an important boost to making the Future Internet vision concrete.
The transition to cloud computing offers a large number of benefits, such as lower capital costs and a highly agile environment. Yet, the development of software engineering practices has not kept pace with this change. Moreover, the design and runtime behavior of cloud based services and the underlying cloud infrastructure are largely decoupled from one another.This paper describes the innovative concepts being developed by CloudWave to utilize the principles of DevOps to create an execution analytics cloud infrastructure where, through the use of programmable monitoring and online data abstraction, much more relevant information for the optimization of the ecosystem is obtained. Required optimizations are subsequently negotiated between the applications and the cloud infrastructure to obtain coordinated adaption of the ecosystem. Additionally, the project is developing the technology for a Feedback Driven Development Standard Development Kit which will utilize the data gathered through execution analytics to supply developers with a powerful mechanism to shorten application development cycles.
This book constitutes the refereed proceedings of four workshops held in conjunction with the Third European Conference, ServiceWave 2010, held in Ghent, Belgium, in December 2010. The book includes 2
The emergence of cloud environments has made feasible the delivery of Internet-scale services by addressing a number of challenges such as live migration, fault tolerance and quality of service. However, current approaches do not tackle key issues related to cloud storage, which are of increasing importance given the enormous amount of data being produced in today's rich digital environment (e.g. by smart phones, social networks, sensors, user generated content). In this paper we present the architecture of a scalable and flexible cloud environment addressing the challenge of providing data-intensive storage cloud services through raising the abstraction level of storage, enabling data mobility across providers, allowing computational and content-centric access to storage and deploying new data-oriented mechanisms for QoS and security guarantees. We also demonstrate the added value and effectiveness of the proposed architecture through two real-life application scenarios from the healthcare and media domains.
The support for complex services delivery is becoming a key point, in current internet technology. Current trends in internet applications are characterized by on demand delivery of ever growing amounts of content. The future internet of services, will have to deliver content intensive applications to users with quality of service and security guarantees. This paper describes the RESERVOIR project and the challenge of a reliable and effective delivery of services as utilities in a commercial scenario. It starts by analyzing the needs of a future infrastructure provider and introducing the key concept of a. service oriented architecture that combines virtualisation-aware grid with grid-aware virtualisation, while being driven by business service management. This article will then focus oil the benefits and the innovations derived from the, RESERVOIR approach. Eventually, a high level view of RESERVOIR general architecture is illustrated.
RESERVOIR project [16] is developing an advanced system and service management approach that will serve as the infrastructure for Cloud Computing and Communications and Future Internet of Services by creative coupling of service virtualization, grid computing, networking and service management techniques. This paper presents work in progress for the integration and management of such systems into a new generation of Managed Service Infrastructure.
Typical businesses have limited expertise in handling disasters; thus, it makes business sense to use external business continuity services. Existing practice is for the business to determine its critical business processes, perform a risk assessment, mitigate as many of these risks as possible, define a continuity plan, and then periodically test this plan at a local IT (information technology) or work-area recovery site. This practice, however, typically imposes limitations as discussed in this paper. We offer enhancements to mitigate these limitations, including the close interlock between the customer and service provider's processes, a shared representation of a customer's environment, and a recovery infrastructure integrating both automation and virtualization. We capture the customer's IT inventory as a recovery configuration and analyze the requirements and available recovery resources to optimize the test schedule of the recovery center and automatically map recovery requirements to resources. We orchestrate recovery deployment through automation. Based on the recovery configuration, we can also determine to what degree the customer can recover within a virtual environment and automatically map the customer to this environment, thereby accruing the benefits of virtualization. These capabilities enhance the client's recovery experience and provide increased flexibility and resource utilization in the recovery data centers.
The emerging cloud-computing paradigm is rapidly gaining momentum as an alternative to traditional IT (information technology). However, contemporary cloud-computing offerings are primarily targeted for Web 2.0-style applications. Only recently have they begun to address the requirements of enterprise solutions, such as support for infrastructure service-level agreements. To address the challenges and deficiencies in the current state of the art, we propose a modular, extensible cloud architecture with intrinsic support for business service management and the federation of clouds. The goal is to facilitate an open, service-based online economy in which resources and services are transparently provisioned and managed across clouds on an on-demand basis at competitive costs with high-quality service. The Reservoir project is motivated by the vision of implementing an architecture that would enable providers of cloud infrastructure to dynamically partner with each other to create a seemingly infinite pool of IT resources while fully preserving their individual autonomy in making technological and business management decisions. To this end, Reservoir could leverage and extend the advantages of virtualization and embed autonomous management in the infrastructure. At the same time, the Reservoir approach aims to achieve a very ambitious goal: creating a foundation for next-generation enterprise-grade cloud computing.
Cloud computing represents the latest phase in the evolution of Internet-based computing. In this paper, we describe the fundamental building blocks of cloud computing and the initiative undertaken by the IBM Research Division in this area, which includes work on Internet-scale data centers, virtualization, scalable storage, and cloud computing services. The focus of this project has been the Research Compute Cloud, an environment for cloud computing research that is also used as a computing resource by various groups in the IBM Research Division.
This paper presents current research in the design and integration of advance systems, service and management technologies into a new generation of Service Infrastructure for Future Internet of Services, which includes Service Clouds Computing. These developments are part of the FP7 RESERVOIR project and represent a creative mixture of service and network virtualisation, service computing, network and service management techniques.
Antonio Puliafito合作论文数Department of Engineering, University of Messina2