|
|||||||||||||||||||||
|
|||||||||||||||||||||
ABSTRACT
However well we protect our systems, there is always a chancethey will be compromised. Constructing practical survivable distributed systems that achieve their goals even after being penetrated is a challenge. The problem manifests itself in algorithms maintaining consistency among servers, in routing protocols, and in the interface between clients (or sensors) and the system. We discuss our recent work on intrusion-tolerant algorithms that scale to wide-area networks. We demonstrate limitations in traditional correctness criteria and in common metrics that, while relevant to small systems, are less meaningful in large and complex environments. We propose new metrics that may better capture the challenge posed by such environments. We also point to gaps where no adequate solutions currently exist. INDEX TERMS
Primary Classification:
|
|||||||||||||||||||||