DocumentCode :
2564703
Title :
Using Byzantine Agreement in the Design Of IPS Systems
Author :
Osorio, Fernando C Colóon
Author_Institution :
Wireless Syst. & Res. Lab., Marlboro, MA
fYear :
2007
fDate :
11-13 April 2007
Firstpage :
528
Lastpage :
537
Abstract :
Intrusion detection, prevention & countermeasure systems (IPS) and architectures commonly used in commercial, as well as research environments, suffer from a number of problems that limit their effectiveness. The most common shortcoming of current IPSs is their inability to survive failures, either generated by typical faults or as a result of a deliberate malicious attack. The Wireless System Security Research Laboratory (WSSRL) attempts to correct this situation by developing a secure architecture and fault-resilient engine (SAFE), a system capable of tolerating such failures. This system makes use of solutions to the Byzantine general´s problem, developed earlier by Lamport, Shostak, and Pease. Byzantine agreement protocols are used to achieve consensus about which nodes have been compromised or failed, with a series of synchronized, secure rounds of message exchanges. Once a consensus has been reached, the offending nodes can be isolated and countermeasure actions can be initiated by the system. In this manuscript, we investigate the necessary and sufficient conditions for the application of Byzantine agreement protocols to the intrusion detection problem. Further, a first implementation of this algorithm is embedded in the distributed trust manager (DTM) module of SAFE, and is discussed. The algorithms are evaluated in terms of performance (i.e., time to achieve resolution) and ability to detect attacks.
Keywords :
protocols; radio networks; telecommunication security; Byzantine agreement protocols; Byzantine general problem; IPS systems; SAFE; Wireless System Security Research Laboratory; distributed trust manager module; intrusion detection prevention & countermeasure systems; malicious attack; secure architecture and fault-resilient engine; Capacitive sensors; Communication system security; Engines; Fault detection; Intrusion detection; Laboratories; Protocols; Redundancy; Scalability; Sufficient conditions;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance, Computing, and Communications Conference, 2007. IPCCC 2007. IEEE Internationa
Conference_Location :
New Orleans, LA
ISSN :
1097-2641
Print_ISBN :
1-4244-1138-6
Electronic_ISBN :
1097-2641
Type :
conf
DOI :
10.1109/PCCC.2007.358936
Filename :
4197972
Link To Document :
بازگشت