Two-Person Control Administation: Preventing Administation Faults through Duplication
نویسندگان
چکیده
Modern computing systems are complex and difficult to administer, making them more prone to system administration faults. Faults can occur simply due to mistakes in the process of administering a complex system. These mistakes can make the system insecure or unavailable. Faults can also occur due to a malicious act of the system administrator. Systems provide little protection against system administrators who install a backdoor or otherwise hide their actions. To prevent these types of system administration faults, we created ISE-T (I See Everything Twice), a system that applies the two-person control model to system administration. ISE-T requires two separate system administrators to perform each administration task. ISE-T then compares the results of the two administrators’ actions for equivalence. ISE-T only applies the results of the actions to the real system if they are equivalent. This provides a higher level of assurance that administration tasks are completed in a manner that will not introduce faults into the system. While the two-person control model is expensive, it is a natural fit for many financial, government, and military systems that require higher levels of assurance. We implemented a prototype ISE-T system for Linux using virtual machines and a unioning file system. Using this system, we conducted a real user study to test its ability to capture changes performed by seperate system administrators and compare them for equivalence. Our results show that ISE-T is effective at determining equivalence for many common administration tasks, even when administrators perform those tasks in different ways.
منابع مشابه
Substance use disorders in the U.S. Armed Forces, 2000-2011.
Drug misuse is associated with serious health consequences and has detrimental effects on military readiness. During 2000 to 2011, 70,104 service members received an incident diagnosis of a substance use disorder (SUD) (excluding alcohol and tobacco-related disorders). Incidence rates declined with increasing age, time in service, rank, and number of combat deployments. Service members in a com...
متن کاملSynergistic killing of glioblastoma stem-like cells by bortezomib and HDAC inhibitors.
BACKGROUND The malignant brain tumour glioblastoma is a devastating disease that remains a therapeutic challenge. MATERIALS AND METHODS Effects of combinations of the US Food and Drug Administation (FDA) approved proteasome inhibitor bortezomib and the histone deacetylase (HDAC) inhibitors vorinostat, valproic acid and sodium phenylbutyrate were studied on primary glioblastoma stem cell lines...
متن کاملCompatibility and stability of palonosetron hydrochloride and propofol during simulated y-site administration.
Palonosetron hydrochloride is a longer-acting, selective 5-HT3 receptor antagonist that has been approved for prevention of chemotherapy-induced nausea and vomiting and is being evaluated for prevention of postoperative nause and vomiting. The objective of this study was to evaluate the physical and chemical stablity of palonosetron hydrochloride 50 mcg/mL when mixed with undiluted propofol 1% ...
متن کاملInstruments for evalutation of altered states of consciousness
In recent years an increase of interest concerning the altered states of consciousness was observed. In particular literature provided a wide amount of contribution about the scales for measurement of level of responsivity. Our aim is to describe the principale scales used in diagnosis of Disorder of Consciousness (DOC) trying to illustrate administation procedures, specifically assessed aspect...
متن کاملComparing Fail-Sailence Provided by Process Duplication versus Internal Error Detection for DHCP Server
This paper uses fault injection to compare the ability of two fault-tolerant software architectures to protect an application from faults. These two architectures are Voltan, which uses process duplication, and Chameleon ARMORs, which use self-checking. The target application is a Dynamic Host Configuration Protocol (DHCP) server, a widely used application for managing IP addresses. NFTAPE, a s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2009