Tolerating Resource Exhaustion Attacks in the Time-Triggered Architecture
Resumo
The Time-Triggered Architecture (TTA) presents a blueprint for building safe and real-time constrained distributed systems, based on a set of orthogonal concepts that make extensive use of the availability of a globally consistent notion of time and a priori knowledge of events. Although the TTA tolerates arbitrary failures of any of its nodes by architectural means (active node replication, a membership service, and bus guardians), the design of these means considers only accidental faults. However, distributed safety- and real-time critical systems have been emerging into more open and interconnected systems, operating autonomously for prolonged times and interfacing with other possibly non-real-time systems. Therefore, the existence of vulnerabilities that adversaries may exploit to compromise system safety cannot be ruled out. In this paper, we discuss potential targeted attacks capable of bypassing TTA's fault-tolerance mechanisms and demonstrate how two well-known recovery techniques --- proactive and reactive rejuvenation --- can be incorporated into TTA to reduce the window of vulnerability for attacks without introducing extensive and costly changes.
Palavras-chave:
time-triggered architecture, proactive recovery, reactive recovery, intrusion-tolerance, safety-critical real-time systems
Publicado
21/11/2022
Como Citar
ALKOUDSI, Mohammad Ibrahim; FOHLER, Gerhard; VÖLP, Marcus.
Tolerating Resource Exhaustion Attacks in the Time-Triggered Architecture. In: SIMPÓSIO BRASILEIRO DE ENGENHARIA DE SISTEMAS COMPUTACIONAIS (SBESC), 12. , 2022, Fortaleza/CE.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2022
.
p. 39-46.
ISSN 2237-5430.