An Architectural Concept for Intrusion Tolerance in Air Traffic Networks

Jeffrey M. Maddalon, Paul S. Miner · 2003

The goal of an intrusion tolerant network is to continue to provide predictable and reliable communication in the presence of a limited number of compromised network components. The behavior of a compromised network component ranges from a node that no longer responds to a node that is under the control of a malicious entity that is actively trying to cause other nodes to fail. Most current data communication networks do not include support for tolerating unconstrained misbehavior of components in the network. However, the fault tolerance community has developed protocols that provide both predictable and reliable communication in the presence of the worst possible behavior of a limited number of nodes in the system. One may view a malicious entity in a communication network as a node that has failed and is behaving in an arbitrary manner. NASA/Langley Research Center has developed one such fault-tolerant computing platform called SPIDER (Scalable Processor-Independent Design for Electromagnetic Resilience). The protocols and interconnection mechanisms of SPIDER may be adapted to large-scale, distributed communication networks such as would be required for future Air Traffic Management systems. The predictability and reliability guarantees provided by the SPIDER protocols have been formally verified. This analysis can be readily adapted to similar network structures.

Read the paper · More papers on PaperTik