Path-based access control for enterprise networks

被引:0
|
作者
Burnside, Matthew [1 ]
Keromytis, Angelos D. [1 ]
机构
[1] Columbia Univ, Dept Comp Sci, New York, NY 10027 USA
来源
关键词
path-based; access control; Keynote; SOA; enterprise;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise networks are ubiquitious and increasingly complex. The mechanisms for defining security policies in these networks have not kept up with the advancements in networking technology. In most cases, system administrators define policies on a per-application basis, and subsequently, these policies do riot interact. For example, there is no mechanism that allows a web server to communicate decisions based on its ruleset to a firewall in front of it, even though decisions being made at the web server may be relevant to decisions at the firewall. In this paper, we describe a path-based access control system for service-oriented architecture (SOA)-style networks which allows services to pass access-control-related information to neighboring services, as the services process requests from outsiders and from each other. Path-based access control defends networks against a class of attacks wherein individual services make correct access control decisions but the resulting global network behavior is incorrect. We demonstrate the system in two forms, using graph-based policies and by leveraging the KeyNote trust management system.
引用
收藏
页码:191 / 203
页数:13
相关论文
共 50 条
  • [31] Path-based set representations
    Robert G. Chambers
    Journal of Productivity Analysis, 2023, 60 : 249 - 256
  • [32] Traffic analysis for multiparty videoconferencing in virtual path-based ATM networks
    Feng, G
    Yum, TSP
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2000, 13 (01) : 79 - 96
  • [33] Path-based extensions of local link prediction methods for complex networks
    Aziz, Furqan
    Gul, Haji
    Uddin, Irfan
    Gkoutos, Georgios, V
    SCIENTIFIC REPORTS, 2020, 10 (01)
  • [34] Path-Based Program Repair
    Riener, Heinz
    Ehlers, Ruediger
    Fey, Goerschwin
    ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2015, (178): : 22 - 32
  • [35] Path-based Optimization of NFV-Resource Allocation in SDN Networks
    Hamann, Malte
    Fischer, Mathias
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [36] Path-based Protection in WDM Networks with Differentiated Quality-of-Protection
    Lin, Yu
    Hamza, Haitham S.
    Deogun, Jitender S.
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2489 - 2494
  • [37] A Semantic Path-Based Similarity Measure for Weighted Heterogeneous Information Networks
    Yang, Chunxue
    Zhao, Chenfei
    Wang, Hengliang
    Qiu, Riming
    Li, Yuan
    Mu, Kedian
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT (KSEM 2018), PT I, 2018, 11061 : 311 - 323
  • [38] Path-Based Fragmentation Metric and RSA Algorithms for Elastic Optical Networks
    Pederzolli, Federico
    Siracusa, Domenico
    Zanardi, Andrea
    Galimberti, Gabriele
    La Fauci, Domenico
    Martinelli, Giovanni
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2019, 11 (03) : 15 - 25
  • [39] Path-based morphological openings
    Heijmans, H
    Buckley, M
    Talbot, H
    ICIP: 2004 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOLS 1- 5, 2004, : 3085 - 3088
  • [40] Path-based supports for hypergraphs
    Brandes, Ulrik
    Cornelsen, Sabine
    Pampel, Barbara
    Sallaberry, Arnaud
    JOURNAL OF DISCRETE ALGORITHMS, 2012, 14 : 248 - 261