Research on intrusion tolerant system using live migrationLive Migration를 이용한 효율적인 침입감내 시스템에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 510
  • Download : 0
Recently, as IT and Internet technology are rapidly developed, information systems are threatened by advanced and sophisticated attacks. One way to support the availability of the systems is an intrusion tolerant system (ITS), which can maintain its critical services under various attacks. In this study, a new ITS based on live migration is proposed for efficiency and resilience against a denial of service (DoS) attack. While conventional ITSs focus on only the exposure time of virtual machines (VMs) to refresh them, the proposed system introduces to use the features of VMs by live migration in addition to the exposure time. In the propose scheme, the system consists of several VMs, and is refreshed periodically and by the live migration. The live migration is one of refreshing methods, which monitors various features of the VMs in order to identify exhausted VMs and refreshes the exhausted VMs into the pristine VMs regardless of expiring the exposure time. The proposed scheme using the live migration provides efficient performance because the system can respond to requests by healthy VMs. Due to monitoring the status of VMs, the system is able to identify exhausted VMs and replace them with new ones easily at the proper time to continue the required services. In addition, for the efficiency and survivability of system, the proposed scheme has the ability to adjust the number of online VMs according to the amount of incoming packets, through which the system can obtain the countermeasure against a DoS attack. To show the efficient performance and security against DoS, the experiments are conduct by CSIM20, which is a process-oriented, discrete-event simulator. We measured the response times of the proposed system and the original system without our proposed scheme. The experimental results with CSIM20 show that our proposed scheme, compared to the recently reported ITS scheme, improves the system performance of 43.77% in terms of the response time in heavy net...
Advisors
Yoon, Hyun-Sooresearcher윤현수
Description
한국과학기술원 : 전산학과,
Publisher
한국과학기술원
Issue Date
2014
Identifier
591846/325007  / 020105343
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전산학과, 2014.8, [ v, 58p ]

Keywords

ITS; 서비스거부공격; 상태변환; 복구; 침임감내시스템; DoS; recovery; live migration

URI
http://hdl.handle.net/10203/197833
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=591846&flag=dissertation
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0