Duo: Software Defined Intrusion Tolerant System Using Dual Cluster

المؤلفون المشاركون

Lee, Yongjae
Lee, Seunghyeon
Seo, Hyunmin
Yoon, Changhoon
Shin, Seungwon
Yoon, Hyunsoo

المصدر

Security and Communication Networks

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-13، 13ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-01-21

دولة النشر

مصر

عدد الصفحات

13

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

An intrusion tolerant system (ITS) is a network security system that is composed of redundant virtual servers that are online only in a short time window, called exposure time.

The servers are periodically recovered to their clean state, and any infected servers are refreshed again, so attackers have insufficient time to succeed in breaking into the servers.

However, there is a conflicting interest in determining exposure time, short for security and long for performance.

In other words, the short exposure time can increase security but requires more servers to run in order to process requests in a timely manner.

In this paper, we propose Duo, an ITS incorporated in SDN, which can reduce exposure time without consuming computing resources.

In Duo, there are two types of servers: some servers with long exposure time (White server) and others with short exposure time (Gray server).

Then, Duo classifies traffic into benign and suspicious with the help of SDN/NFV technology that also allows dynamically forwarding the classified traffic to White and Gray servers, respectively, based on the classification result.

By reducing exposure time of a set of servers, Duo can decrease exposure time on average.

We have implemented the prototype of Duo and evaluated its performance in a realistic environment.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Lee, Yongjae& Lee, Seunghyeon& Seo, Hyunmin& Yoon, Changhoon& Shin, Seungwon& Yoon, Hyunsoo. 2018. Duo: Software Defined Intrusion Tolerant System Using Dual Cluster. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-13.
https://search.emarefa.net/detail/BIM-1214306

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Lee, Yongjae…[et al.]. Duo: Software Defined Intrusion Tolerant System Using Dual Cluster. Security and Communication Networks No. 2018 (2018), pp.1-13.
https://search.emarefa.net/detail/BIM-1214306

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Lee, Yongjae& Lee, Seunghyeon& Seo, Hyunmin& Yoon, Changhoon& Shin, Seungwon& Yoon, Hyunsoo. Duo: Software Defined Intrusion Tolerant System Using Dual Cluster. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-13.
https://search.emarefa.net/detail/BIM-1214306

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1214306