DocumentCode
2175579
Title
The design and implementation of an intrusion tolerant system
Author
Reynolds, James ; Just, James ; Lawson, Ed ; Clough, Larry ; Maglich, Ryan ; Levitt, Karl
fYear
2002
fDate
2002
Firstpage
285
Lastpage
290
Abstract
We describe the implementation of an intrusion tolerant system for providing Internet services to known users through secure connections. Network attacks are treated as maliciously devised conditions to exploit design, implementation, or configuration faults, intrusions (successful attacks) are treated as failures, and their effects are mitigated by using the three pillars of fault tolerance: detection, isolation, and recovery. Fundamental to our approach is the use of diverse process pairs, which provides partial solutions to detection and isolation problems. The architecture uses the comparison of outputs from diverse applications to provide a significant and novel intrusion detection capability. The diverse applications also strengthen isolation by forcing attacks to exploit independent vulnerabilities. The isolation of intrusions is mainly achieved with an out-of-band control system. The control system not only provides separation between the primary and backup system, it also initiates attack diagnosis, attack blocking, and recovery, which is accelerated by on-line repair.
Keywords
Internet; computer network reliability; security of data; telecommunication security; Internet services; attack blocking; attack diagnosis; configuration faults; fault tolerance; intrusion tolerant system design; network attacks; online repair; out-of-band control system; secure connections; software architecture; Computer networks; Control systems; Fault detection; Fault tolerance; Fault tolerant systems; Hardware; Intrusion detection; Local area networks; Virtual private networks; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks, 2002. DSN 2002. Proceedings. International Conference on
Print_ISBN
0-7695-1101-5
Type
conf
DOI
10.1109/DSN.2002.1028912
Filename
1028912
Link To Document