Path-based access control for enterprise networks

被引:0
|
作者
Burnside, Matthew [1 ]
Keromytis, Angelos D. [1 ]
机构
[1] Columbia Univ, Dept Comp Sci, New York, NY 10027 USA
来源
关键词
path-based; access control; Keynote; SOA; enterprise;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise networks are ubiquitious and increasingly complex. The mechanisms for defining security policies in these networks have not kept up with the advancements in networking technology. In most cases, system administrators define policies on a per-application basis, and subsequently, these policies do riot interact. For example, there is no mechanism that allows a web server to communicate decisions based on its ruleset to a firewall in front of it, even though decisions being made at the web server may be relevant to decisions at the firewall. In this paper, we describe a path-based access control system for service-oriented architecture (SOA)-style networks which allows services to pass access-control-related information to neighboring services, as the services process requests from outsiders and from each other. Path-based access control defends networks against a class of attacks wherein individual services make correct access control decisions but the resulting global network behavior is incorrect. We demonstrate the system in two forms, using graph-based policies and by leveraging the KeyNote trust management system.
引用
收藏
页码:191 / 203
页数:13
相关论文
共 50 条
  • [21] Critical Path-Based Backdoor Detection for Deep Neural Networks
    Jiang, Wei
    Wen, Xiangyu
    Zhan, Jinyu
    Wang, Xupeng
    Song, Ziwei
    Bian, Chen
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (03) : 4032 - 4046
  • [22] Accurate Path-based Methods for Influence Maximization in Social Networks
    Ko, Yun-Yong
    Chae, Dong-Kyu
    Kim, Sang-Wook
    PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW'16 COMPANION), 2016, : 59 - 60
  • [23] An efficient path-based approach for influence maximization in social networks
    Kianian, Sahar
    Rostamnia, Mehran
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 167
  • [24] Path-Based Differential in Multi-Modal Brain Networks
    Falakshahi, Haleh
    Rokham, Hooman
    Calhoun, Vince
    BIOLOGICAL PSYCHIATRY, 2022, 91 (09) : S329 - S329
  • [25] Path-based approach to integrated planning and control for robotic systems
    Tarn, TJ
    Xi, N
    Bejczy, AK
    AUTOMATICA, 1996, 32 (12) : 1675 - 1687
  • [26] Path-based set representations
    Chambers, Robert G.
    JOURNAL OF PRODUCTIVITY ANALYSIS, 2023, 60 (03) : 249 - 256
  • [27] Path-Based Supports for Hypergraphs
    Brandes, Ulrik
    Cornelsen, Sabine
    Pampel, Barbara
    Sallaberry, Arnaud
    COMBINATORIAL ALGORITHMS, 2011, 6460 : 20 - +
  • [28] Path-based morphological openings
    CWI, Kruislaan 413, 1098 SJ Amsterdam, Netherlands
    不详
    1600, 3085-3088 (2004):
  • [29] Restoration of all-optical mesh networks with path-based flooding
    Kim, SI
    Lumetta, SS
    JOURNAL OF LIGHTWAVE TECHNOLOGY, 2003, 21 (11) : 2605 - 2616
  • [30] Situational Awareness based Risk-adaptable Access Control in Enterprise Networks
    Lee, Brian
    Vanickis, Roman
    Rogelio, Franklin
    Jacob, Paul
    IOTBDS: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY, 2017, : 400 - 405