Title :
Intrusion tolerant Web servers via network layer controls
Abstract :
Summary form only given. This demonstration shows the approach taken on the Intrusion Tolerant Server Infrastructure (ITSI) program to identify and isolate intrusions, prevent them from freely spreading, and continue to provide service to benign users while recovering from the intrusion. The distinguishing feature of the ITSI approach is the use of "smart NIC" to help identify intrusions, and, once an intrusion has been detected, to contain it and ensure that service is uninterrupted by providing a failover capability. These smart NIC are based on the distributed firewall technology developed by Secure Computing on DARPA\´s Autonomic Distributed Firewall (ADF) program. The ADF NIC has been enhanced on the ITSI program to support multi-server load sharing, to enable load shifting in the face of attacks, and to provide an alert capability when unauthorized traffic is detected. The demonstration prototype uses two heterogeneous Web servers: Apache running on SELinux and IIS running on Windows 2000. The demonstration shows how various attacks are detected and how the smart NIC can be used to respond to an attack in a manner that ensures that the Web service will continue to operate.
Keywords :
Internet; authorisation; fault tolerant computing; military computing; resource allocation; ADF program; Apache; Autonomic Distributed Firewall program; DARPA; IIS; ITSI program; Intrusion Tolerant Server Infrastructure; SELinux; Secure Computing; Windows 2000; alert capability; failover capability; heterogeneous Web servers; intrusion isolation; intrusion tolerant Web servers; multi-server load sharing; network layer controls; smart NIC; unauthorized traffic; Computer crime; Control systems; Distributed computing; Face detection; Gas detectors; Information security; Intrusion detection; Prototypes; Web server; Web services;
Conference_Titel :
DARPA Information Survivability Conference and Exposition, 2003. Proceedings
Print_ISBN :
0-7695-1897-4
DOI :
10.1109/DISCEX.2003.1194948