DocumentCode
2310342
Title
Finite Memory: A Vulnerability of Intrusion-Tolerant Systems
Author
Veronese, G.S. ; Correia, Miguel ; Lung, L.C. ; Verissimo, Paulo
Author_Institution
Fac. de Cienc., LASIGE, Univ. de Lisboa, Lisbon
fYear
2008
fDate
10-12 July 2008
Firstpage
37
Lastpage
44
Abstract
In environments like the Internet, faults follow unusual patterns, dictated by the combination of malicious attacks with accidental faults such as long communication delays caused by temporary network partitions. In this scenario, attackers can force buffer overflows in order to leave the system in an inconsistent state or to prevent it from doing progress, causing a denial of service. This paper is about the effects that finite memory has on intrusion-tolerant protocols and systems. We present the problem and propose a generic mitigation technique based on repair nodes that reduces the buffer space requirements. An experimental evaluation of the buffer usage with and without this technique is presented, allowing to assess in practice the effects of finite memory in a real, albeit simple, intrusion-tolerant system.
Keywords
Internet; security of data; storage management; Internet; buffer space requirement; buffer usage; denial of service; finite memory; generic mitigation technique; intrusion tolerant protocol; intrusion tolerant system; malicious attack; Buffer overflow; Buffer storage; Computer applications; Computer crime; Computer networks; Computer security; Delay; Fault tolerant systems; IP networks; Protocols; Buffer Management; Byzantine Fault Tolerance; Garbage Collection.; Intrusion Tolerance;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Computing and Applications, 2008. NCA '08. Seventh IEEE International Symposium on
Conference_Location
Cambridge, MA
Print_ISBN
978-0-7695-3192-2
Electronic_ISBN
978-0-7695-3192-2
Type
conf
DOI
10.1109/NCA.2008.40
Filename
4579637
Link To Document