Path-based access control for enterprise networks

被引:0
|
作者
Burnside, Matthew [1 ]
Keromytis, Angelos D. [1 ]
机构
[1] Columbia Univ, Dept Comp Sci, New York, NY 10027 USA
来源
关键词
path-based; access control; Keynote; SOA; enterprise;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise networks are ubiquitious and increasingly complex. The mechanisms for defining security policies in these networks have not kept up with the advancements in networking technology. In most cases, system administrators define policies on a per-application basis, and subsequently, these policies do riot interact. For example, there is no mechanism that allows a web server to communicate decisions based on its ruleset to a firewall in front of it, even though decisions being made at the web server may be relevant to decisions at the firewall. In this paper, we describe a path-based access control system for service-oriented architecture (SOA)-style networks which allows services to pass access-control-related information to neighboring services, as the services process requests from outsiders and from each other. Path-based access control defends networks against a class of attacks wherein individual services make correct access control decisions but the resulting global network behavior is incorrect. We demonstrate the system in two forms, using graph-based policies and by leveraging the KeyNote trust management system.
引用
收藏
页码:191 / 203
页数:13
相关论文
共 50 条
  • [1] Path-Based Epidemic Spreading in Networks
    Chai, Wei Koong
    Pavlou, George
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (01) : 565 - 578
  • [2] Path-Based Recovery in Flexgrid Optical Networks
    Castro, A.
    Ruiz, M.
    Velasco, L.
    Junyent, G.
    Comellas, J.
    2012 14TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON 2012), 2012,
  • [3] Distributed Path-Based Inference in Semantic Networks
    Chain-Wu Lee
    Chun-Hsi Huang
    Laurence Tianruo Yang
    Sanguthevar Rajasekaran
    The Journal of Supercomputing, 2004, 29 : 211 - 227
  • [4] Distributed path-based inference in semantic networks
    Lee, CW
    Huang, CH
    Rajasekaran, S
    Yang, LT
    Hsu, DF
    I-SPAN 2004: 7TH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND NETWORKS, PROCEEDINGS, 2004, : 232 - 237
  • [5] Distributed path-based inference in semantic networks
    Lee, CW
    Huang, CH
    Yang, LTR
    JOURNAL OF SUPERCOMPUTING, 2004, 29 (02): : 211 - 227
  • [6] On Rich Clubs of Path-Based Centralities in Networks
    Sarkar, Soumya
    Bhowmick, Sanjukta
    Mukherjee, Animesh
    CIKM'18: PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, 2018, : 567 - 576
  • [7] Alternative Path-based Congestion Control in Many-To-One Sensor Networks
    Zhao, Kunliang
    Liu, Weidong
    Wong, Ming Sze
    Song, Jiaxing
    2010 5TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2010,
  • [8] Improving Web Applications Security Using Path-Based Role Access Control Model
    Kononov, Dmitry
    Isaev, Sergey
    PROCEEDINGS OF THE 2018 3RD RUSSIAN-PACIFIC CONFERENCE ON COMPUTER TECHNOLOGY AND APPLICATIONS (RPC), 2018,
  • [9] A Path-Based Feature Selection Algorithm for Enterprise Credit Risk Evaluation
    Du, Marui
    Ma, Yue
    Zhang, Zuoquan
    Computational Intelligence and Neuroscience, 2022, 2022
  • [10] A Path-Based Feature Selection Algorithm for Enterprise Credit Risk Evaluation
    Du, Marui
    Ma, Yue
    Zhang, Zuoquan
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022