首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >The Design of a Generic Intrusion-Tolerant Architecture for Web Servers
【24h】

The Design of a Generic Intrusion-Tolerant Architecture for Web Servers

机译:Web服务器的通用入侵容忍体系结构的设计

获取原文
获取原文并翻译 | 示例

摘要

Nowadays, more and more information systems are connected to the Internet and offer Web interfaces to the general public or to a restricted set of users. Such openness makes them likely targets for intruders, and conventional protection techniques have been shown insufficient to prevent all intrusions in such open systems. This paper proposes a generic architecture to implement intrusion-tolerant Web servers. This architecture is based on redundancy and diversification principles, in order to increase the system resilience to attacks: usually, an attack targets a particular software, running on a particular platform, and fails on others. The architecture is composed of redundant proxies that mediate client requests to a redundant bank of diversified COTSfootnote{Commercial Off The Shelf.} application servers. The redundancy is deployed here to increase system availability and integrity. To improve performance, adaptive redundancy is applied: the redundancy level is selected according to the current alert level. The architecture can be used for static servers, i.e., for Web distribution of stable information (updated off-line), as well as for fully dynamic systems where information updates are executed immediately on an on-line database. The feasibility of this architecture has been demonstrated by implementing an example of a travel agency Web server.
机译:如今,越来越多的信息系统连接到Internet,并为普通大众或有限的用户提供Web界面。这种开放性使得它们很可能成为入侵者的目标,而传统的保护技术已被证明不足以防止此类开放系统中的所有入侵。本文提出了一种通用架构来实现入侵容忍Web服务器。此体系结构基于冗余和多样化原则,以增强系统对攻击的适应能力:通常,攻击针对的是运行在特定平台上的特定软件,而在其他平台上失败的攻击。该体系结构由冗余代理组成,这些代理将客户端请求调解到多个COTSfootnote {Commercial Off the Shelf。}应用服务器的冗余库中。此处部署了冗余以提高系统可用性和完整性。为了提高性能,应用了自适应冗余:根据当前警报级别选择冗余级别。该体系结构可用于静态服务器,即用于稳定信息的Web分发(离线更新),以及用于在在线数据库上立即执行信息更新的全动态系统。通过实现旅行社Web服务器的示例已证明了此体系结构的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号