Passer à la navigation principale Passer à la recherche Passer au contenu principal

A dependable intrusion detection architecture based on agreement services

  • Michel Hurfin
  • , Jean Pierre Le Narzul
  • , Frédéric Majorczyk
  • , Ludovic Mé
  • , Ayda Saidane
  • , Eric Totel
  • , Frédéric Tronel
  • IRISA
  • ENST Bretagne
  • Supelec

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

In this paper, we show that the use of diversified COTS servers allows to detect intrusions corresponding to unknown attacks. We present an architecture that ensures both confidentiality and integrity at the COTS server level and we extend it to enhance availability. Replication techniques implemented on top of agreement services are used to avoid any single point of failure. On the one hand we assume that COTS servers are complex softwares that contain some vulnerabilities and thus may exhibit arbitrary behaviors. While on the other hand other basic components of the proposed architecture are simple enough to be exhaustively verified. That's why we assume that they can only suffer from crash failures. The whole system is assumed to be asynchronous and furthermore messages can be lost. In the particular case of Web servers connected to databases, we identify the properties that have to be maintained and the alarms that have to be raised. We describe in details how the different replicated levels interact together and, for each level, we precise the reasons that have led us to use a particular agreement service. Performance evaluations are conducted to measure the quality of service of the Intrusion Detection System (quantity of false positives and lack of false negatives) and the additional cost induced by the mechanisms used to ensure the availability of this secure architecture.

langue originaleAnglais
titreStabilization, Safety, and Security of Distributed Systems - 8th International Symposium, SSS 2006. Proceedings
EditeurSpringer Verlag
Pages378-394
Nombre de pages17
ISBN (imprimé)3540490183, 9783540490180
Les DOIs
étatPublié - 1 janv. 2006
Modification externeOui
Evénement8th International Symposium on Self-Stabilizing Systems, SSS 2006 - Dallas, TX, États-Unis
Durée: 17 nov. 200619 nov. 2006

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4280 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence8th International Symposium on Self-Stabilizing Systems, SSS 2006
Pays/TerritoireÉtats-Unis
La villeDallas, TX
période17/11/0619/11/06

Empreinte digitale

Examiner les sujets de recherche de « A dependable intrusion detection architecture based on agreement services ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation