• DocumentCode
    446479
  • Title

    Instant attack stopper in InfiniBand architecture

  • Author

    Lee, Manhee ; Kim, Eun Jung ; Ki Hwan Yum ; Yousif, Mazin

  • Author_Institution
    Dept. of Comput. Sci., Texas A&M Univ., College Station, TX, USA
  • Volume
    1
  • fYear
    2005
  • fDate
    9-12 May 2005
  • Firstpage
    105
  • Abstract
    With the growing popularity of cluster architectures in datacenters and the sophistication of computer attacks, the design of highly secure clusters has recently emerged as a critical design issue. However, the majority of cluster security research has focused on how to detect and prevent attacks rather than on how to minimize the effect of attacks once detected. The action against detected attacks in the cluster is as important as the actual detection process since no detection mechanism is full-proof in its ability to protect cluster systems without the effective cluster-wide reaction. In this paper, we propose a scheme, referred to as the instant attack stopper (IAS) that can instantly confront security attacks in a cluster. Specifically we provide detailed implementation methods of IAS in InfiniBand architecture (IBA) - a new promising communication standard for future system area networks (SANs) and clusters. IAS focuses on removing malicious communication on the IBA fabric among processes involved in an attack, which is accomplished through the proposed security management agent (SeMA). We will show IAS deployment in different security levels to meet various security requirements.
  • Keywords
    security of data; workstation clusters; InfiniBand architecture; attack detection; cluster architectures; cluster security; cluster system protection; computer attacks; datacenters; highly secure clusters; instant attack stopper; malicious communication; security management agent; system area networks; Communication standards; Communication system security; Computer architecture; Computer errors; Computer hacking; Data security; High performance computing; Intrusion detection; Protection; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cluster Computing and the Grid, 2005. CCGrid 2005. IEEE International Symposium on
  • Print_ISBN
    0-7803-9074-1
  • Type

    conf

  • DOI
    10.1109/CCGRID.2005.1558541
  • Filename
    1558541