ByzID: Byzantine Fault Tolerance from Intrusion Detection

被引:14
作者
Duan, Sisi [1 ]
Levitt, Karl [1 ]
Hein Meling [2 ]
Peisert, Sean [1 ,3 ]
Zhang, Haibin [1 ]
机构
[1] Univ Calif Davis, Davis, CA 95616 USA
[2] Univ Stavanger, Stavanger, Norway
[3] LBNL, Berkeley, CA USA
来源
2014 IEEE 33RD INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS) | 2014年
关键词
CONSENSUS; TIME; SYSTEM;
D O I
10.1109/SRDS.2014.28
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Building robust network services that can withstand a wide range of failure types is a fundamental problem in distributed systems. The most general approach, called Byzantine fault tolerance, can mask arbitrary failures. Yet it is often considered too costly to deploy in practice, and many solutions are not resilient to performance attacks. To address this concern we leverage two key technologies already widely deployed in cloud computing infrastructures: replicated state machines and intrusion detection systems. First, we have designed a general framework for constructing Byzantine failure detectors based on an intrusion detection system. Based on such a failure detector, we have designed and built a practical Byzantine fault-tolerant protocol, which has costs comparable to crash-resilient protocols like Paxos. More importantly, our protocol is particularly robust against several key attacks such as flooding attacks, timing attacks, and fairness attacks, that are typically not handled well by Byzantine fault masking procedures.
引用
收藏
页码:253 / 264
页数:12
相关论文
共 38 条
[1]  
Alsberg P. A., 1976, ICSE
[2]   Prime: Byzantine Replication under Attack [J].
Amir, Yair ;
Coan, Brian ;
Kirsch, Jonathan ;
Lane, John .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2011, 8 (04) :564-577
[3]  
Baldoni R., 2000, DSN
[4]  
Budhiraja N., 1993, Distributed systems
[5]  
Burrows Mike., 2006, OSDI
[6]  
Castro M., 1999, OSDI
[7]   Unreliable failure detectors for reliable distributed systems [J].
Chandra, TD ;
Toueg, S .
JOURNAL OF THE ACM, 1996, 43 (02) :225-267
[8]  
Chun B., 2007, SOSP
[9]  
Clement A., 2009, NSDI
[10]  
Clement A., 2012, PODC