Surviving Internet Catastrophes

Surviving Internet Catastrophes
复制标题

渡过互联网灾难

DOI:
10.1109/hase.2010.19
复制
发表时间:
2005
期刊:
2010 IEEE 12th International Symposium on High Assurance Systems Engineering
影响因子:
--
通讯作者:
G. Voelker
G. Voelker
中科院分区:
--
文献类型:
--
作者:
F. Junqueira;Ranjita Bhagwan;A. Hevia;K. Marzullo;G. Voelker

文献摘要

被引文献

相似文献

在本文中,我们提出了一种新的方法来设计分布式系统生存的互联网灾难称为通知复制,并证明这种方法的设计和评估的合作备份系统称为凤凰恢复服务。知情复制使用相关故障模型来利用软件多样性。使我们的方法既可行又实用的关键观察是,互联网灾难是由共同的漏洞造成的。通过在没有相同漏洞的主机上复制系统服务,利用漏洞的Internet病原体不太可能导致所有副本失败。为了表征软件多样性在互联网环境中,我们衡量主机操作系统和网络服务在一个大型组织的软件多样性。然后,我们使用我们的测量研究的见解来开发和评估计算副本集,有一些有吸引力的功能的算法。我们的数据库提供了出色的可靠性保证,导致低程度的复制,限制了系统中每个主机的存储负担,并适合于完全分布式的实施。然后,我们提出了凤凰的设计和原型实现,并评估它的PlanetLab测试平台。
In this paper, we propose a new approach for designing distributed systems to survive Internet catastrophes called informed replication, and demonstrate this approach with the design and evaluation of a cooperative backup system called the Phoenix Recovery Service. Informed replication uses a model of correlated failures to exploit software diversity. The key observation that makes our approach both feasible and practical is that Internet catastrophes result from shared vulnerabilities. By replicating a system service on hosts that do not have the same vulnerabilities, an Internet pathogen that exploits a vulnerability is unlikely to cause all replicas to fail. To characterize software diversity in an Internet setting, we measure the software diversity of host operating systems and network services in a large organization. We then use insights from our measurement study to develop and evaluate heuristics for computing replica sets that have a number of attractive features. Our heuristics provide excellent reliability guarantees, result in low degree of replication, limit the storage burden on each host in the system, and lend themselves to a fully distributed implementation. We then present the design and prototype implementation of Phoenix, and evaluate it on the PlanetLab testbed.