%0 Conference Paper %D 2002 %T Formal specification and verification of a group membership protocol for an intrusion-tolerant group communication system %A Ramasamy,H. V. %A Michel Cukier %A Sanders,W. H. %K computer network reliability %K distributed processing %K distributed systems %K fault tolerant computing %K formal specification %K formal verification %K group membership protocol %K intrusion-tolerant group communication system %K PROMELA %K Protocols %X We describe a group membership protocol that is part of an intrusion-tolerant group communication system, and present an effort to use formal tools to model and validate our protocol. We describe in detail the most difficult part of the validation exercise, which was the determination of the right level of abstraction of the protocol for formally specifying the protocol. The validation exercise not only formally showed that the protocol satisfies its correctness claims, but also provided information that will help us make the protocol more efficient without violating correctness. %P 9 - 18 %8 2002/12// %G eng %R 10.1109/PRDC.2002.1185613