The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

An Exploration of Highly Focused, Coprocessor-based Information System Protection

Download

Download PDF Document
PDF

Author

Paul Williams and Eugene H. Spafford

Tech report number

CERIAS TR 2007-66

Entry type

article

Abstract

Most past and present intrusion detection systems architectures assume a uniprocessor environment or do not explicitly make use of multiple processors when they exist. Yet, especially in the server world, multiple processor machines are commonplace; and with the advent of technologies such as Intel and ANID's multi-core or Hyperthreading technologies, commodity computers are likely to have multiple processors. This research explores how explicitly dividing the system into production and security components and running the components in parallel on different processors can improve the effectiveness of the security system. The production component contains all user tasks and most of the operating system while the security component contains security monitoring and validating tasks and the parts of the O/S that pertain to security. We demonstrate that under some circumstances this architecture allows intrusion detection systems to use monitoring models with higher fidelity, particularly with regard to the timeliness of detection, and will also increase system robustness in the face of some types of attacks. Empirical results with a prototype co-processing intrusion detection system (Cu-PIDS) architecture support the feasibility of this approach. The construction of the prototype allowed us to demonstrate the implementation costs of the architecture are reasonable. Experimentation using fine-grained protection of real-world applications resulted in about a fifteen percent slowdown white demonstrating CuPIDS' ability to quickly detect and respond to illegitimate behavior.

Download

PDF

Date

2007 – 04

Journal

Computer Networks

Key alpha

Williams

Note

No link to PDF

Pages

1284-1298

Publisher

Elsevier

Volume

V 51(5)

Affiliation

Purdue University

Publication Date

2007-04-01

Keywords

Coprocessor-based, Information System, Protection

Language

English

Subject

Coprocessor-based Information System Protection

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.