Quantitative Approach to Tuning of a Time-Based Intrusion-Tolerant System Architecture
Quyen Thi Tu Nguyen, Arun K. Sood · 2009
Many institutions rely on open systems to provide services to the public via the Internet. Unanticipated software vulnerabilities expose such services to malicious actors, and make them susceptible to attacks. Therefore, security is critical in order to ensure confidentiality, integrity, and availability for system data and services. The fact that security attacks have become increasingly sophisticated makes the protection of open systems more challenging. Current intrusion prevention and detection are reactive, and the bad guys are always one step ahead. In this paper, we will present a quantitative analysis of Self-Cleansing Intrusion Tolerance (SCIT), a time-based intrusion tolerance architecture. Using quantitative techniques we show that it is possible to tune a SCIT system based on its exposure window in order to achieve the required degree of intrusion tolerance. 1.