Path-based access control for enterprise networks

被引:0
|
作者
Burnside, Matthew [1 ]
Keromytis, Angelos D. [1 ]
机构
[1] Columbia Univ, Dept Comp Sci, New York, NY 10027 USA
来源
关键词
path-based; access control; Keynote; SOA; enterprise;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise networks are ubiquitious and increasingly complex. The mechanisms for defining security policies in these networks have not kept up with the advancements in networking technology. In most cases, system administrators define policies on a per-application basis, and subsequently, these policies do riot interact. For example, there is no mechanism that allows a web server to communicate decisions based on its ruleset to a firewall in front of it, even though decisions being made at the web server may be relevant to decisions at the firewall. In this paper, we describe a path-based access control system for service-oriented architecture (SOA)-style networks which allows services to pass access-control-related information to neighboring services, as the services process requests from outsiders and from each other. Path-based access control defends networks against a class of attacks wherein individual services make correct access control decisions but the resulting global network behavior is incorrect. We demonstrate the system in two forms, using graph-based policies and by leveraging the KeyNote trust management system.
引用
收藏
页码:191 / 203
页数:13
相关论文
共 50 条
  • [41] Design of a fast restoration mechanism for virtual path-based ATM networks
    Hou, CJ
    IEEE INFOCOM '97 - THE CONFERENCE ON COMPUTER COMMUNICATIONS, PROCEEDINGS, VOLS 1-3: SIXTEENTH ANNUAL JOINT CONFERENCE OF THE IEEE COMPUTER AND COMMUNICATIONS SOCIETIES - DRIVING THE INFORMATION REVOLUTION, 1997, : 361 - 369
  • [42] Path-based extensions of local link prediction methods for complex networks
    Furqan Aziz
    Haji Gul
    Irfan Uddin
    Georgios V. Gkoutos
    Scientific Reports, 10
  • [43] Shortest path-based analysis of protein-protein interaction networks
    Li, Min
    Chen, Jianer
    Wang, Jianxin
    Gaojishu Tongxin/Chinese High Technology Letters, 2009, 19 (01): : 89 - 94
  • [44] The path-based minimum power broadcast problem in static wireless networks
    Lin, Frank Yeong-Sung
    Wen, Yean-Fu
    Fu, Lin-Chih
    Lin, Shu-Ping
    TENCON 2005 - 2005 IEEE REGION 10 CONFERENCE, VOLS 1-5, 2006, : 1354 - 1359
  • [45] Efficient path-based multicast in wormhole-routed mesh networks
    Chen, TS
    Chang, CY
    Sheu, JP
    JOURNAL OF SYSTEMS ARCHITECTURE, 2000, 46 (10) : 919 - 930
  • [46] Bagging for path-based clustering
    Fischer, B
    Buhmann, JM
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2003, 25 (11) : 1411 - 1415
  • [47] PATH-BASED SCHEDULING FOR SYNTHESIS
    CAMPOSANO, R
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 1991, 10 (01) : 85 - 93
  • [48] Tractability of path-based inheritance
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (02):
  • [49] Path-based buffer insertion
    Sze, C. N.
    Alpert, Charles J.
    Hu, Jiang
    Shi, Weiping
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2007, 26 (07) : 1346 - 1355
  • [50] Path-based multicasting in multicomputers
    Harutyunyan, H.
    Wang, S.
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING AND NETWORKS, 2007, : 220 - +