A cyber-resilient architecture for critical security services

被引:11
作者
Kreutz, Diego [1 ,2 ]
Malichevskyy, Oleksandr [2 ]
Feitosa, Eduardo [3 ]
Cunha, Hugo [3 ]
Righi, Rodrigo da Rosa [4 ]
de Macedo, Douglas D. J. [5 ]
机构
[1] Univ Luxembourg, SnT, Luxembourg, Luxembourg
[2] FCUL, LaSIGE, Lisbon, Portugal
[3] Univ Fed Amazonas, IComp, Manaus, Amazonas, Brazil
[4] Univ Vale Rio dos Sinos, Sao Leopoldo, Brazil
[5] UFS, Aracaju, Brazil
关键词
Cyber resiliency; Cyber security; System design; Fault and intrusion tolerance; Identification and authentication services; Network access control; INTRUSION; MIDDLEWARE;
D O I
10.1016/j.jnca.2015.09.014
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Authentication and authorization are two of the most important services for any IT infrastructure. Taking into account the current state of affairs of cyber warfare, the security and dependability of such services is a first class priority. For instance, the correct and continuous operation of identity providers (e.g., OpenID) and authentication, authorization and accounting services (e.g., RADIUS) is essential for all sorts of systems and infrastructures. As a step towards this direction, we introduce a functional architecture and system design artifacts for prototyping fault- and intrusion-tolerant identification and authentication services. The feasibility and applicability of the proposed elements are evaluated through two distinct prototypes. Our findings indicate that building and deploying resilient and reliable critical services is an achievable goal through a set of system design artifacts based on well-established concepts in the fields of security and dependability. Additionally, we provide an extensive evaluation of both resilient RADIUS (R-RADIUS) and OpenID (R-OpenID) prototypes. We show that our solution makes services resilient against attacks without affecting their correct operation. Our results also pinpoint that the prototypes are capable of meeting the needs of small to large-scale systems (e.g., IT infrastructures with 800k to 10M users). (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:173 / 189
页数:17
相关论文
共 87 条
  • [1] Alchieri Eduardo A. P., 2008, 2008 IEEE International Conference on Web Services (ICWS), P21, DOI 10.1109/ICWS.2008.54
  • [2] AlZain M. A., 2012, 2012 45th Hawaii International Conference on System Sciences (HICSS), P5490, DOI 10.1109/HICSS.2012.153
  • [3] Amazon Web Services Inc, 2014, AM EC2 PRIC
  • [4] [Anonymous], 2013, P 2 ACM SIGCOMM WORK, DOI DOI 10.1145/2491185.2491199
  • [5] [Anonymous], 2014, WHITEHOUSE NEWS OCT
  • [6] [Anonymous], TECHNICAL REPORT
  • [7] [Anonymous], PROC 12TH IFIP WG 6
  • [8] [Anonymous], 2014, SOFTWARE DEFINED NET
  • [9] [Anonymous], 2013, 6929 RFC
  • [10] [Anonymous], POSITION PAPERS OF T