Proceedings of the IEEK Conference (대한전자공학회:학술대회논문집)
- 2003.07d
- /
- Pages.1359-1362
- /
- 2003
Implementation of a Web Service Intrusion Tolerance System based on Diversity and Redundancy
다양성과 중복성을 이용한 웹 서비스 침입감내 시스템 구현
Abstract
The intrusions appears continuously by new unknown attacks exploiting vulnerabilities of systems or components but there are no perfect solutions to protect this unknown attacks. To overcome this problem, in this paper, we have proposed and implemented a Web service intrusion tolerant system that provides continuous Web services to the end users transparently even after the occurrence of an attack against the Web services, and prevents the disclosure of system's configuration data from server Our system has an N+l node architecture which is to minimize the number of redundant server nodes and to tolerate the intrusion effectively, and it also supports diversity in its design. Experimental result obtained on an implemented system show that our system can cope with intrusion such as DoS, file modification, confidentiality compromise of system properly.
Keywords