• DocumentCode
    970946
  • Title

    Highly Available Intrusion-Tolerant Services with Proactive-Reactive Recovery

  • Author

    Sousa, Paulo ; Bessani, Alysson Neves ; Correia, Miguel ; Neves, Nuno Ferreira ; Verissimo, Paulo

  • Author_Institution
    Dep. de Inf., Univ. Lisboa, Lisbon, Portugal
  • Volume
    21
  • Issue
    4
  • fYear
    2010
  • fDate
    4/1/2010 12:00:00 AM
  • Firstpage
    452
  • Lastpage
    465
  • Abstract
    In the past, some research has been done on how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that enhances proactive recovery with additional reactive mechanisms giving correct replicas the capability of recovering other replicas that are detected or suspected of being compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of a minimum number of system replicas necessary to sustain correct operation of the system. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to increase the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures.
  • Keywords
    authorisation; distributed processing; software fault tolerance; system recovery; fault production; hybrid distributed system model; intrusion-tolerant firewall; intrusion-tolerant replicated systems; proactive-reactive recovery service; system deployment time; Intrusion tolerance; firewall.; proactive recovery; reactive recovery;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2009.83
  • Filename
    5010435