New intrusion tolerance software fortifies server secrurity
In spite of increased focus and large investments in computer security, critical infrastructure systems remain vulnerable to attacks, says Arun Sood, professor of computer science at George Mason University. The increasing sophistication and incessant morphing of cyber-attacks lend importance to the concept of intrusion tolerance: a system must fend off, or at least limit, the damage caused by unknown and/or undetected attacks. "The problem is that no matter how much investment is made in intrusion prevention and detection, intruders will still manage to break through and trespass on computer servers," says Sood. "By looking at this problem from a different angle, we developed a way to contain the losses that may occur because of an intrusion."
Sood, who is the director of the Laboratory of Interdisciplinary Computer Science at Mason, along with Yin Huang, senior research scientist in the Center for Secure Information Systems at Mason, created the Self Cleansing Intrusion Tolerance (SCIT) technology to provide an additional layer of defense to security architecture with firewalls and intrusion prevention and detection systems. While typical approaches to computer security are reactive and require prior knowledge of all attack modalities and software vulnerabilities, intrusion tolerance is a proactive approach to security.
In the SCIT approach, a server that has been online is assumed to have been compromised. SCIT servers are focused on limiting the losses that can occur because of an external intrusion, and achieve this goal by limiting the exposure time of the server to the Internet. Exposure time is defined as. the duration of time that a server is continuously connected to the Internet. Through the use of virtualization technology, duplicate servers are created and an online server is periodically cleansed and restored to a known clean state, regardless of whether an intrusion has been detected. These regular cleansings take place in sub-minute intervals.
"This approach of regular cleansings, when coupled with existing intrusion prevention and detection systems, leads to increased overall security," says Sood. "We know that intrusion detection systems can detect sudden increases in data throughput from a server, so to avoid detection, hackers steal data at low rates. SCIT interrupts the flow of data regularly and automatically, and the data ex-filtration process is interrupted every cleansing cycle. Thus, SCIT, in partnership with intrusion detection systems, limits the volume of data that can be stolen."
By reducing exposure time, SCIT provides an additional level of protection while efforts are ongoing to find and fix vulnerabilities and correct configuration errors.
Source: George Mason University
Related
- US must focus on protecting critical computer networks from cyber attack, RAND study findsThu, 8 Oct 2009, 12:17:31 EDT
- Argonne develops program for cyber security 'neighborhood watch'Thu, 16 Jul 2009, 16:15:28 EDT
- How secure is your network? NIST model knowsWed, 23 Jul 2008, 15:14:41 EDT
- Denial of service denialWed, 30 Sep 2009, 13:57:21 EDT
- Good code, bad computations: A computer security gray areaMon, 27 Oct 2008, 15:56:44 EDT
Other sources
- New Intrusion Tolerance Software Fortifies Server Securityfrom Science DailyWed, 18 Jun 2008, 14:28:10 EDT
- New intrusion tolerance software fortifies server secrurityfrom PhysorgMon, 16 Jun 2008, 15:07:15 EDT
Latest Science Newsletter
Get the latest and most popular science news articles of the week in your Inbox!Popular science news articles
- Scientists uncover new key to the puzzle of hormone therapy and breast cancer
- Failing the sniff test: Researchers find new way to spot fraud
- Indiana U. at APHA: Studies about why men and women use lubricants during sex
- Remains of Minoan-style painting discovered during excavations of Canaanite palace
- Young tennis players who play only 1 sport are more prone to injuries
- African desert rift confirmed as new ocean in the making
- 1 shot of gene therapy and children with congenital blindness can now see
- Scientists discover influenza's Achilles heel: Antioxidants
- Cleanliness is next to godliness: New research shows clean smells promote moral behavior
- Super typhoon Lupit heading west in the Philippine Sea