Title
The Design of a Generic Intrusion-Tolerant Architecture for Web Servers
Abstract
Nowadays, more and more information systems are connected to the Internet and offer Web interfaces to the general public or to a restricted set of users. Such openness makes them likely targets for intruders, and conventional protection techniques have been shown insufficient to prevent all intrusions in such open systems. This paper proposes a generic architecture to implement intrusion-tolerant Web servers. This architecture is based on redundancy and diversification principles in order to increase the system resilience to attacks: usually, an attack targets a particular software, running on a particular platform, and fails on others. The architecture is composed of redundant proxies that mediate client requests to a redundant bank of diversified application servers. The redundancy is deployed here to increase system availability and integrity. To improve performance, adaptive redundancy is applied: the redundancy level is selected according to the current alert level. The architecture can be used for static servers, that is, for Web distribution of stable information (updated offline) and for fully dynamic systems where information updates are executed immediately on an online database. The feasibility of this architecture has been demonstrated by implementing an example of a travel agency Web server, and the first performance tests are satisfactory, both for request execution times and recovery after incidents.
Year
DOI
Venue
2009
10.1109/TDSC.2008.1
Dependable and Secure Computing, IEEE Transactions
Keywords
Field
DocType
Internet,client-server systems,data integrity,fault tolerant computing,file servers,open systems,redundancy,security of data,Internet,Web interface,Web server,adaptive redundancy,client-server system,data integrity,diversification principle,information system,intrusion-tolerant architecture,open system,system availability,Security,Web servers,and protection,integrity
Computer science,Server,Redundancy (engineering),Intrusion tolerance,Reference architecture,Application software,Service-oriented architecture,Distributed computing,Web server,Application server
Journal
Volume
Issue
ISSN
6
1
1545-5971
Citations 
PageRank 
References 
28
1.59
9
Authors
3
Name
Order
Citations
PageRank
Saidane, Ayda1281.59
Vincent Nicomette211520.90
Yves Deswarte31142156.24