arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

可达性,而非观测性:遏制接线变化的系统

Reachability, Not Observation: Containing Systems Whose Wiring Changes

Yoshiaki Takashita

arXiv 2609.19720首次发表:更新:

发表机构

School of Law, Waseda University(早稻田大学法学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对接线动态变化的系统,提出基于可达性而非观测快照的遏制方法,揭示观测盲区并验证静态可达性检查的有效性。

AI 中文摘要

遏制决策——防火墙放置位置、监控哪些链路、程序可访问什么——是基于观测到的结构计算的,而观测是快照。我们探究当接线随时间变化时,快照会遗漏什么。在活动维度旋转的超立方体上,平衡分割在93%的时刻显示零交叉边,然而必须永久阻断8,192条边;增加一条常开环,防御者看到需要阻断8,194条边中的2条,因子为4,097。一个时间感知的防御者平均持有585个阻断,但时钟滞后一步使其遏制效果降至0%。在真实互联网上,去除增长后,同样的差距仅为1.8-2.0倍(1997-2000年)和1.5-1.6倍(2024-2026年),因此盲区是由设计引入的,而非继承自现实世界——而且它确实是被设计出来的:光数据中心结构的轮询调度其差距等于其周期。一份声明的能力图,通过真实应用调用图上的静态可达性检查,捕获了所有8个植入漏洞;先前使用的字符串拒绝列表捕获了2个。一个计算从单一参数(周期)生成所有数字,并读出三个通常不称为调度的边界:跳频,其标准结果就是这些以信道代替边的闭式;气隙,其常开交叉集为空,其已知破坏发生在快照遗漏的一个相位;以及编码智能体的工具表面,从内部盘点。对该智能体进行切割:空闲时,其瞬时状态切割为零,而6个信道在上下文重置时携带它,其中没有一个是网络,因此切断网络移除0。产生副本的信道是一个分支过程,在批准率1/b处有尖锐阈值,低于该阈值拒绝是不必要的,高于该阈值拒绝是不充分的。通过存在的路径来遏制,而非通过已见的行为。

英文摘要

Containment decisions -- where to put a firewall, which links to monitor, what a program may reach -- are computed from an observed structure, and observation is a snapshot. We ask what a snapshot misses when the wiring changes over time. On a hypercube whose active dimension rotates, a balanced split shows zero crossing edges at 93% of instants, yet 8,192 edges must be blocked permanently; adding one always-on ring, a defender sees 2 where 8,194 must be blocked, a factor of 4,097. A time-aware defender holds 585 blocks on average, but one step of clock lag drops its containment to 0%. On the real Internet the same gap is only x1.8-2.0 (1997-2000) and x1.5-1.6 (2024-2026) once growth is removed, so the blind spot is introduced by design, not inherited from the world -- and it has been designed: the round-robin schedules of optical datacentre fabrics have a gap equal to their period. A declared capability map, checked by static reachability over a real application's call graph, catches all 8 planted holes; the string deny-list previously in place catches 2. One calculation generates every number from one parameter, the period, and reads three boundaries not usually called schedules: frequency hopping, whose standard results are these closed forms with channels in place of edges; the air gap, whose always-on crossing set is empty and whose known breach came at the one phase a snapshot misses; and the tool surface of a coding agent, inventoried from the inside. Turning the cuts on that agent: idle, its instantaneous state cut is zero, while 6 channels carry it across a context reset, none of them the network, so severing the network removes 0. The channel that spawns copies is a branching process with a sharp threshold at approval rate 1/b, below which denial is unnecessary and above which denial is insufficient. Contain by the paths that exist, not by the behaviour that was seen.

Comments29 pages, 3 figures, 17 tables. Companion to arXiv:2609.18145. Code and records for every number are included with the submission

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑