• DocumentCode
    1630006
  • Title

    Design and implementation of acceptance monitor for building scalable intrusion tolerant system

  • Author

    Wang, Rong ; Wang, Feiyi ; Byrd, Gregory T.

  • Author_Institution
    Adv. Networking Res., MCNC, Research Triangle Park, NC, USA
  • fYear
    2001
  • fDate
    6/23/1905 12:00:00 AM
  • Firstpage
    200
  • Lastpage
    205
  • Abstract
    Intrusion detection research has so far mostly concentrated on techniques that effectively identify malicious behavior. No assurance can be assumed once the system is compromised. Intrusion tolerance, on the other hand, focuses on providing minimal level of services even when some components have been partially compromised. The challenges here are how to take advantage of fault tolerant techniques in the intrusion tolerant system context and how to deal with possible unknown attacks and compromised components so as to continue providing the service. This paper presents our work on applying one important fault tolerance technique, acceptance testing, for building scalable intrusion tolerant systems. First, we propose a general methodology for designing acceptance tests. An acceptance monitor architecture is proposed to apply various tests for detecting compromises based on the impact of the attacks. Second, we make a comprehensive vulnerability analysis on typical commercial-off-the-shelf (COTS) Web servers. Various acceptance testing modules are implemented to show the effectiveness of the proposed approach. By utilizing the fault tolerance techniques on intrusion tolerance system, we provide a mechanism for building reliable distributed services that are more resistant to both known and unknown attacks
  • Keywords
    Internet; computerised monitoring; fault tolerant computing; file servers; security of data; supervisory programs; telecommunication security; testing; COTS Web servers; acceptance monitor; acceptance testing; commercial-off-the-shelf Web servers; compromise detection; distributed services; fault tolerance computing; intrusion detection; network security; partially compromised components; scalable intrusion tolerance; vulnerability analysis; Buildings; Context-aware services; Design methodology; Fault tolerance; Fault tolerant systems; Information security; Intrusion detection; Monitoring; System testing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2001. Proceedings. Tenth International Conference on
  • Conference_Location
    Scottsdale, AZ
  • ISSN
    1095-2055
  • Print_ISBN
    0-7803-7128-3
  • Type

    conf

  • DOI
    10.1109/ICCCN.2001.956241
  • Filename
    956241