Abstract
In this work, we present a first effort at quantitatively comparing the strengths and limitations of various intrusion-tolerant server architectures. We study four representative architectures, and use stochastic models to quantify the costs and benefits of each from both the performance and dependability perspectives. We present results characterizing throughput and availability, the effectiveness of architectural defense mechanisms, and the impact of the performance versus dependability tradeoff. We believe that the results of this evaluation will help system architects to make informed choices for building more secure and survivable server systems.
This research has been supported by DARPA contract F30602-00-C-0172.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Cardellini, V., Colajanni, M., Yu, P.S.: Dynamic Load Balancing on Web-server Systems. IEEE Internet Computing 3(3), 28–39 (1999)
Castro, M., Liskov, B.: Practical Byzantine Fault Tolerance. In: Proc. Third Symp. on Operating Sys. Design and Implementation (OSDI 1999), pp. 173–186 (1999)
Cukier, M., Lyons, J., Pandey, P., Ramasamy, H.V., Sanders, W.H., Pal, P., Webber, F., Schantz, R., Loyall, J., Watro, R., Atighetchi, M., Gossett, J.: Intrusion Tolerance Approaches in ITUA. In: Fast Abstract in Supplement of the 2001 International Conference on Dependable Systems and Networks, pp. B64–B65 (2001)
Deavours, D.D., Clark, G., Courtney, T., Daly, D., Derisavi, S., Doyle, J.M., Sanders, W.H., Webster, P.G.: The Möbius Framework and Its Implementation. IEEE Trans. on Software Engineering 28(10), 956–969 (2002)
Delis, A., Roussopoulos, N.: Performance and Scalability of Client-Server Database Architectures. In: Proc. Intl Conf. in Very Large Data Bases (VLDB), pp. 610–623 (1992)
Deswarte, Y., Blain, L., Fabre, J.C.: Intrusion Tolerance in Distributed Computing Systems. In: Proc. IEEE Symposium on Security and Privacy, pp. 110–121 (1991)
Draper Laboratories, Inc., Kinetic Application of Redundancy to Mitigate Attacks, DARPA OASIS Program, http://www.tolerantsystems.org/ProjectSummaries/IT_Using_Masking_Redundancy_and_Dispersion.html
Gupta, V., Lam, V., Ramasamy, H.V., Sanders, W.H., Singh, S.: Dependability and Performance Evaluation of Intrusion-Tolerant Server Architectures. CRHC Technical Report (2003) (to appear)
Lindqvist, U., Olovsson, T., Jonsson, E.: An Analysis of a Secure System Based on Trusted Components. In: Proc. Eleventh Annual Conf. on Computer Assurance (COMPASS 1996), Gaithersburg, Maryland, pp. 213–223 (1996)
Ramasamy, H.V., Pandey, P., Lyons, J., Cukier, M., Sanders, W.H.: Quantifying the Cost of Providing Intrusion Tolerance in Group Communication Systems. In: Proc. Intl Conf. on Dependable Sys. and Networks (DSN 2002), pp. 229–238 (2002)
Sanders, W.H., Cukier, M., Webber, F., Pal, P., Watro, R.: Probabilistic Validation of Intrusion Tolerance. In: Fast Abstract in Supplemental Volume of the 2002 International Conference on Dependable Systems and Networks, pp. B78–B79 (2002)
Sanders, W.H., Meyer, J.F.: Stochastic Activity Networks: Formal Definitions and Concepts. In: Brinksma, E., Hermanns, H., Katoen, J.-P. (eds.) EEF School 2000 and FMPA 2000. LNCS, vol. 2090, pp. 315–343. Springer, Heidelberg (2001)
Schneider, F.: Implementing Fault-Tolerant Services Using the State Machine Approach: A Tutorial. ACM Computing Surveys 22(4), 299–319 (1990)
Secure Computing Corporation, Intrusion Tolerant Server Infrastructure, DARPA OASIS Program, http://www.tolerantsystems.org/ProjectSummaries/_Intrusion_Tolerant_Server_Infrastructure.html
Singh, S., Cukier, M., Sanders, W.H.: Probabilistic Validation of an Intrusion- Tolerant Replication System. In: Proc. Intl Conf. on Dependable Sys. and Networking (DSN 2003), pp. 615–624 (2003)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2003 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Gupta, V., Lam, V., Ramasamy, H.V., Sanders, W.H., Singh, S. (2003). Dependability and Performance Evaluation of Intrusion-Tolerant Server Architectures. In: de Lemos, R., Weber, T.S., Camargo, J.B. (eds) Dependable Computing. LADC 2003. Lecture Notes in Computer Science, vol 2847. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-45214-0_9
Download citation
DOI: https://doi.org/10.1007/978-3-540-45214-0_9
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-20224-0
Online ISBN: 978-3-540-45214-0
eBook Packages: Springer Book Archive