Title :
IDRS: Combining File-level Intrusion Detection with Block-level Data Recovery based on iSCSI
Author :
Zhang, Youhui ; Wang, Hongyi ; Gu, Yu ; Wang, Dongsheng
Author_Institution :
Tsinghua Nat. Lab. for Inf. Sci. & Technol. Dept. of Electron. Eng., Tsinghua Univ., Beijing
Abstract :
Over the past years, researches on the intrusion detection have been parallelized with those on data recovery. Most of them scarcely try to combine the two issues together to propose an integrated solution, which is employed to defend the pivotal data and to recover the data when the intrusion has taken place. In this paper, we propose a framework of intrusion detection/recovery system (IDRS). This system is capable of detecting the intrusion on the file-level and recovering data on the block-level. Its advantages include that the file-level detection simplifies the implementation and the recovery based on the block-level can decrease the recovery time and raise the utilization ratio of storage devices. Again, considering that iSCSI has increasingly played an important role in network storage systems, we implement the IDRS prototype based on this promising protocol. The result of tests shows the extra storage overheads, arising from IDRS, are small (less than 10%). Therefore, we believe it is feasible to deploy IRDS on iSCSI systems to protect key files from damage.
Keywords :
digital storage; file organisation; security of data; IDRS; block-level data recovery; file-level intrusion detection; iSCSI; network storage systems; Availability; Data engineering; Data security; Information science; Information security; Intrusion detection; Laboratories; National security; Protection; Protocols;
Conference_Titel :
Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-0-7695-3102-1
DOI :
10.1109/ARES.2008.59