{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:27:02Z","timestamp":1760243222621,"version":"build-2065373602"},"reference-count":16,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2014,11,13]],"date-time":"2014-11-13T00:00:00Z","timestamp":1415836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"NRF, MEST","award":["2014R1A2A2-A01006957"],"award-info":[{"award-number":["2014R1A2A2-A01006957"]}]},{"name":"MKE\/KEIT","award":["10041244"],"award-info":[{"award-number":["10041244"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Improvements in networking technologies have provided users with useful information services. Such information services may bring convenience and efficiency, but might be accompanied by vulnerabilities to a variety of attacks. Therefore, a variety of research to enhance the security of the systems and get the services at the same time has been carried out. Especially, research on intrusion-tolerant systems (ITSs) has been conducted in order to survive against every intrusion, rather than to detect and prevent them. In this paper, an ITS based on effective resource conversion (ERC) is presented to achieve the goal of intrusion-tolerance. Instead of using the fixed number of virtual machines (VMs) to process requests and recover as in conventional approaches, the ITS based on ERC can transform the assigned resources depending on the system status. This scheme is proved to maintain a certain level of quality of service (QoS) and quality of security service (QoSS) in threatening environments. The performance of ERC is compared with previous studies on ITS by CSIM 20, and it is verified that the proposed scheme is more effective in retaining a specific level of QoS and QoSS.<\/jats:p>","DOI":"10.3390\/sym6040938","type":"journal-article","created":{"date-parts":[[2014,11,13]],"date-time":"2014-11-13T11:22:30Z","timestamp":1415877750000},"page":"938-953","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Design of a Secure System Considering Quality of Service"],"prefix":"10.3390","volume":"6","author":[{"given":"Seondong","family":"Heo","sequence":"first","affiliation":[{"name":"Department of Computer Science, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 305-701, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Soojin","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Korea National Defense University, 33 Je2Jayuro, Goyang-si, Gyeonggi-do 412-706, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seokjoo","family":"Doo","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering, Korea Army Academy at Yeong-cheon, 495 Hogukro, Gogyeong-myeon, Yeongcheon-si, Gyeongbuk 770-849, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyunsoo","family":"Yoon","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Korea Advanced Institute of Science and Technology, 291 Daehak-ro, Yuseong-gu, Daejeon 305-701, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2014,11,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Malkawi, M.I. (2013). The art of software systems development: Reliability, availability, maintainability, performance (RAMP). Hum.-Centric Comput. Inf. Sci., 3.","DOI":"10.1186\/2192-1962-3-22"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Jingle, I.D.J., and Rajsingh, E.B. (2014). ColShield: An effective and collaborative protection shield for the detection and prevention of collaborative flooding of DDoS attacks in wireless mesh networks. Hum.-Centric Comput. Inf. Sci., 4.","DOI":"10.1186\/s13673-014-0008-8"},{"key":"ref_3","first-page":"23","article-title":"Lightweight anonymous authentication scheme with unlinkabilty in global mobilty networks","volume":"4","author":"Chung","year":"2013","journal-title":"J. Converg."},{"key":"ref_4","unstructured":"Kahate, A. (2013). Cryptography and Network Security, McGraw Hill Education. [3rd ed]."},{"key":"ref_5","unstructured":"Wang, F., Gong, F., Sargor, R., Goseva-Popstojanova, K., Trivedi, K., and Jou, F. (2001, January 5\u20136). SITAR: A Scalable Intrusion Tolerance Architecture for Distributed Services, New York, NY, USA."},{"key":"ref_6","unstructured":"Chong, J., Partha, P., Atigetchi, M., Rubel, P., and Wevver, F. (2005, January 5\u20139). Survivability architecture of a mission critical system: The DPASA example, Tucson, AZ, USA."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1109\/TDSC.2008.1","article-title":"The design of a generic intrusion-tolerant architecture for Web Servers","volume":"6","author":"Saidane","year":"2009","journal-title":"IEEE Trans. Dependable Sec. Comput."},{"key":"ref_8","unstructured":"Sood, A., and Nguyen, Q. (July, January 28). Realizing S-Reliability for Services via Recovery-driven Intrusion Tolerance Mechanism, Chicago, IL, USA."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"452","DOI":"10.1109\/TPDS.2009.83","article-title":"Highly Available Intrusion-Tolerant Services with Proactive-Reactive Recovery","volume":"21","author":"Sousa","year":"2010","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Irvine, C., and Levin, T. (2000, January 18\u201321). Quality of security service, Cork, Ireland.","DOI":"10.21236\/ADA572032"},{"key":"ref_11","unstructured":"Schwetman, H. (2001, January 9\u201312). CSIM19: A Powerful Tool for Building System Models, Arlington, VA, USA."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"918","DOI":"10.1007\/s11227-013-0928-5","article-title":"A novel adaptive cluster transformation (ACT)-based intrusion tolerant system for hybrid information technology","volume":"66","author":"Lim","year":"2013","journal-title":"J. Supercomput."},{"key":"ref_13","first-page":"904","article-title":"A design of a novel intrusion tolerant system using virtual machine image analysis and secure exposure policy","volume":"22","author":"Kim","year":"2012","journal-title":"Telecommun. Rev."},{"key":"ref_14","unstructured":"Stankovic, V., Bessani, A., Daidone, A., Gashi, I., Olbelheiro, R.R., and Sousa, P. (2009, January 29). Enhancing Fault\/Intrusion Tolerance through Design and Configuration Diversity, Lisbon, Portugal."},{"key":"ref_15","unstructured":"Available online: http:\/\/www.wired.com\/images_blogs\/threatlevel\/2012\/03\/Verizon-Data-Breach-Report-2012.pdf."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1007\/978-94-007-5860-5_9","article-title":"A Novel Intrusion Tolerant System Based on Adaptive Recovery Scheme (ARS)","volume":"215","author":"Heo","year":"2013","journal-title":"Lect. Notes Electr. Eng."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/6\/4\/938\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T21:09:19Z","timestamp":1760216959000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/6\/4\/938"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,13]]},"references-count":16,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2014,12]]}},"alternative-id":["sym6040938"],"URL":"https:\/\/doi.org\/10.3390\/sym6040938","relation":{},"ISSN":["2073-8994"],"issn-type":[{"type":"electronic","value":"2073-8994"}],"subject":[],"published":{"date-parts":[[2014,11,13]]}}}