Skip to main content

Intrusion-Tolerant System Design for Web Server Survivability

  • Conference paper

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 2908))

Abstract

Internet becomes more and more popular, and most companies and institutes use web services for e-business to promote their business. As results, Internet and web services become core infrastructure for a business and become more and more important, but attacks against web services increase as the popularity of web services grows. Therefore, there are increasing needs of undisrupted web services despite of attacks. In this paper, contrast to previous approaches that detect and filter known attacks using known vulnerabilities and patterns, we proposed an intrusion tolerant system that can tolerate known vulnerabilities as well as unknown vulnerabilities by providing adaptation, redundancy and diversity. After detecting attacks, the system provides continuous web services using server adaptation and request filtering.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   84.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Computer Security Institute/Federal Bureau of Investigation: Computer crime and security survey (2001)

    Google Scholar 

  2. Symantec Corp.: Symantec internet security threat report, vol. i (2002)

    Google Scholar 

  3. Ellison, B., Fisher, D.A., Linger, R.C., Lipson, H.F., Longstaff, T., Mead, N.R.: Survivable network systems: An emerging discipline. Technical Report CMU/SEI- 97-TR-013, Carnegie-Mellon University Software Engineering Institute (1997)

    Google Scholar 

  4. Pal, P., Webber, F., Schantz, R.E., Loyall, J.P.: Intrusion tolerant systems. In: Proceedings of the IEEE Information Survivability Workshop, Boston, Massachusetts, U.S.A. (2000)

    Google Scholar 

  5. Lee, W., Fan, W.: Mining system audit data: opportunities and challenges. ACM SIGMOD Record 30, 35–44 (2001)

    Article  Google Scholar 

  6. Pal, P., Webber, F., Schantz, R.: Survival by defense-enabling. In: Proceedings of the 2001 workshop on New security paradigms, pp. 71–78. ACM Press, New York (2001)

    Chapter  Google Scholar 

  7. Rathi, M., Anjum, F., Zbib, R., Ghosh, A., Umar, A.: Investigation of intrusion tolerance for COTS middleware. In: Proceedings of the IEEE International Conference on Communications 2002, vol. 2, pp. 1169–1173 (2002)

    Google Scholar 

  8. Stavridou, V., Dutertre, B., Riemenschneider, R.A., Saidi, H.: Intrusion tolerant software architectures. In: Proceedings of the DARPA Information Survivability Conference & Exposition (DISCEX) 2001, vol. 2, pp. 230–241 (2001)

    Google Scholar 

  9. Wang, F., Upppalli, R.: SITAR: a scalable instrusion-tolerant architecture for distributed services - a technology summary. In: Proceedings of the DARPA Information Survivability Conference & Exposition (DISCEX) 2003, vol. 2, pp. 153–155 (2003)

    Google Scholar 

  10. Wang, R., Wang, F., Byrd, G.T.: Design and implementation of acceptance monitor for building scalable intrusion tolerant system. In: Proceedings of the Tenth International Conference on Computer Communications and Networks, Scottsdale, AZ, USA, pp. 200–205 (2001)

    Google Scholar 

  11. Wang, F., Gong, F., Sargor, C., Goseva-Popstojanova, K., Trivedi, K., Jou, F.: SITAR: A scalable intrusion-tolerant architecture for distributed services. In: Proceedings of the 2001 IEEE Workshop on Information Assurance and Security, United States Military Academy, West Point, NY, pp. 38–45 (2001)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2004 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Choi, DS., Im, E.G., Lee, CW. (2004). Intrusion-Tolerant System Design for Web Server Survivability. In: Chae, KJ., Yung, M. (eds) Information Security Applications. WISA 2003. Lecture Notes in Computer Science, vol 2908. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-24591-9_10

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-24591-9_10

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-20827-3

  • Online ISBN: 978-3-540-24591-9

  • eBook Packages: Springer Book Archive

Publish with us

Policies and ethics