Title :
Analysis of techniques for building intrusion tolerant server systems
Author :
Wang, Feiyi ; Uppalli, Raghavendra ; Killian, Charles
Author_Institution :
Adv. Networking Res., MCNC Res. & Dev. Inst., Research Triangle Park, NC, USA
Abstract :
The theme of intrusion detection systems (IDS) is detection because prevention mechanisms alone are not guaranteed to keep intruders out. The research focus of IDS is therefore on how to detect as many attacks as possible, as soon as we can, and at the same time to reduce the false alarm rate. However, a growing recognition is that a variety of mission critical applications need to continue to operate or provide a minimal level of services even when they are under attack or have been partially compromised; hence the need for intrusion tolerance. The goal of this paper is to identify common techniques for building highly available and intrusion tolerant server systems and characterize with examples how various techniques are applied in different application domains. Further, we want to point out the potential pitfalls as well as challenging open research issues which need to be addressed before intrusion tolerant systems (ITS) become prevalent and truly useful beyond a specific range of applications.
Keywords :
military communication; network servers; telecommunication security; false alarm rate; intrusion detection systems; intrusion tolerant server systems; mission critical applications; Degradation; Fault tolerance; Hardware; Intrusion detection; Mission critical systems; Network servers; Potential well; Protection; Redundancy; Software testing;
Conference_Titel :
Military Communications Conference, 2003. MILCOM '03. 2003 IEEE
Print_ISBN :
0-7803-8140-8
DOI :
10.1109/MILCOM.2003.1290202