Title :
Trading resiliency for security: model and algorithms
Author :
Bu, Tian ; Norden, Samphel ; Woo, Thomas
Abstract :
An attack-resistant network is a purpose-built network to survive attacks; by construction, it should be both resilient and secure. Resiliency is the ability to provide alternative communication paths should one path become disrupted due to failures or attacks; while security is the ability to contain and limit the impact of compromises. Interestingly, these two can present conflicting demands. We provide a first formulation of a new class of problems focusing on the engineering of attack-resistant networks. Our model considers both resiliency and security, and uses a notion of blocking probability as a rigorous measure for evaluating different network constructions. We propose several efficient approximation algorithms for computing blocking probability and provide bounds for their errors. Based on these algorithms, we introduce a family of heuristics to guide the construction of optimal attack-resistant networks with minimum blocking probabilities. We also present extensive results to evaluate and demonstrate the near-optimal performance of our heuristics and approximation algorithms.
Keywords :
Internet; probability; telecommunication security; Internet; attack-resistant network; computing blocking probability; purpose-built network; security model; Approximation algorithms; Computer crime; Filtering; Heuristic algorithms; Internet; Multiprocessor interconnection networks; Network servers; Resists; Routing protocols; Security;
Conference_Titel :
Network Protocols, 2004. ICNP 2004. Proceedings of the 12th IEEE International Conference on
Print_ISBN :
0-7695-2161-4
DOI :
10.1109/ICNP.2004.1348112