J4 ›› 2011, Vol. 29 ›› Issue (4): 348-355.

• 论文 • 上一篇    下一篇

基于失效检测算法的容忍入侵系统

赵辉1,2,房至一2,李万龙1,郑山红1   

  1. 1. 长春工业大学 计算机科学与工程学院|长春 130021;2. 吉林大学 计算机科学与技术学院|长春 130012
  • 出版日期:2011-07-25 发布日期:2011-11-28
  • 作者简介:赵辉(1972—)|女|长春人|长春工业大学副教授, 吉林大学博士研究生|主要从事系统结构、信息安全研究|(Tel)86-13074367546(E-mail)zhaohui@mail.ccut.edu.cn
  • 基金资助:

    吉林省教育厅自然科学基金资助项目(200675)

Intrusion Tolerance System Based on Failure Detector Algorithm

ZHAO Hui1,2,FANG Zhi-yi2,LI Wan-long1,ZHENG Shan-hong1   

  1. 1. Institute of Computer Science and Engineering, Changchun University of Technology, Changchun 130012, China;
    2. College of Computer Science and Technology, Jilin University, Changchun 130012, China
  • Online:2011-07-25 Published:2011-11-28

摘要:

为解决容忍入侵系统的自适应能力差和运行效率低等问题,将失效检测和多样化冗余技术相结合,构建具有自适应恢复能力的容忍入侵系统,给出了系统的体系结构,设计了适合于容侵系统的失效检测算法。系统可以区分节点级和服务级的失效,从而采取不同的屏蔽措施和恢复策略,保证系统在受到攻击和入侵后,及时对系统进行重配置。实验结果表明,笔者设计的失效检测算法能解决由于网络延迟和丢包造成的误判问题,检测的准确性明显提高。

关键词: 失效检测, 容忍入侵, 表决机制, 自适应

Abstract:

An intrusion tolerance system that provides self-adaptation and recovery ability is built based on failure detector and diverse redundancy technology,proposing the architecture of the system, and designing the failure detector algorithm for the intrusion-tolerance system. This system can distinguish node\|level and service-level failure,taking different shielding measures and recovery strategies assuring the system be reconfigured in time after being attacked and intruded.The result of experiment shows that the failure detector algorithm can solve the wrong judgement problem caused by network latency and packet loss.The accuracy of detection is clearly improved.

Key words: failure detector, intrusion tolerance, vote mechanism, self-adaptation

中图分类号: 

  • TP3