• DocumentCode
    2175579
  • Title

    The design and implementation of an intrusion tolerant system

  • Author

    Reynolds, James ; Just, James ; Lawson, Ed ; Clough, Larry ; Maglich, Ryan ; Levitt, Karl

  • fYear
    2002
  • fDate
    2002
  • Firstpage
    285
  • Lastpage
    290
  • Abstract
    We describe the implementation of an intrusion tolerant system for providing Internet services to known users through secure connections. Network attacks are treated as maliciously devised conditions to exploit design, implementation, or configuration faults, intrusions (successful attacks) are treated as failures, and their effects are mitigated by using the three pillars of fault tolerance: detection, isolation, and recovery. Fundamental to our approach is the use of diverse process pairs, which provides partial solutions to detection and isolation problems. The architecture uses the comparison of outputs from diverse applications to provide a significant and novel intrusion detection capability. The diverse applications also strengthen isolation by forcing attacks to exploit independent vulnerabilities. The isolation of intrusions is mainly achieved with an out-of-band control system. The control system not only provides separation between the primary and backup system, it also initiates attack diagnosis, attack blocking, and recovery, which is accelerated by on-line repair.
  • Keywords
    Internet; computer network reliability; security of data; telecommunication security; Internet services; attack blocking; attack diagnosis; configuration faults; fault tolerance; intrusion tolerant system design; network attacks; online repair; out-of-band control system; secure connections; software architecture; Computer networks; Control systems; Fault detection; Fault tolerance; Fault tolerant systems; Hardware; Intrusion detection; Local area networks; Virtual private networks; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2002. DSN 2002. Proceedings. International Conference on
  • Print_ISBN
    0-7695-1101-5
  • Type

    conf

  • DOI
    10.1109/DSN.2002.1028912
  • Filename
    1028912