DocumentCode
2176118
Title
Evaluating the security threat of firewall data corruption caused by instruction transient errors
Author
Chen, Shuo ; Xu, Jun ; Iyer, Ravishankar K. ; Whisnant, Keith
Author_Institution
Center for Reliable & High Performance Comput., Illinois Univ., Urbana, IL, USA
fYear
2002
fDate
2002
Firstpage
495
Lastpage
504
Abstract
This paper experimentally evaluates and models the error-caused security vulnerabilities and the resulting security violations of two Linux kernel firewalls: IPChains and Netfilter. There are two major aspects to this work: to conduct extensive error injection experiments on the Linux kernel and to quantify the possibility of error-caused security violations using a SAN (Stochastic Activity Network) model. The error injection experiments show that about 2% of errors injected into the firewall code segment cause security vulnerabilities. Two types of error-caused security vulnerabilities are distinguished: temporary, which disappear when the error disappears, and permanent, which persist even after the error is removed, as long as the system is not rebooted. Results from simulating the SAN model indicate that under an error rate of 0.1 error/day during a 1-year period in a networked system protected by 20 firewalls, 2 machines (on the average) will experience security violations. This indicates that error-caused security vulnerabilities can be a non-negligible source of a security threats to a highly secure system.
Keywords
Unix; authorisation; computer network reliability; network operating systems; telecommunication security; IPChains; Linux kernel; Netfilter; SAN model; Stochastic Activity Network; error injection; error-caused security vulnerabilities; experiment; firewall data corruption; highly secure system; instruction transient errors; security threat; security violations; Computer aided instruction; Cryptography; Data security; Error analysis; Hardware; Kernel; Law; Legal factors; Protection; Storage area networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks, 2002. DSN 2002. Proceedings. International Conference on
Print_ISBN
0-7695-1101-5
Type
conf
DOI
10.1109/DSN.2002.1028938
Filename
1028938
Link To Document