DocumentCode :
1707036
Title :
Software mediators for transparent channel control in unbounded environments
Author :
Hanebutte, N. ; Oman, Paul ; Loosbrock, Michael ; Holland, Austin ; Harrison, W. Scott ; Alves-Foss, Jim
Author_Institution :
Center for Secure & Dependable Syst., Idaho Univ., Moscow, ID, USA
fYear :
2005
Firstpage :
201
Lastpage :
206
Abstract :
Establishing verifiably secure communications is a daunting task, especially in unbounded computing networks such as the Internet and the global information grid. The multiple independent levels of security (MILS) architecture has been developed to facilitate this task. Wrappers, filters and mediators, both hardware and software, have been proposed as MILS mechanisms to enforce communication security policies such as data isolation and sanitation. This paper describes two experimental projects showing how software mediators can be implemented using CORBA in two different environments: a standard Unix TCP/IP network with multiple workstations, and a single board computer running the integrity operating system with a separation kernel supporting multiple isolated execution environments. The first example shows how protocol mediators can enforce communication-related security policies on standard networks, while the second shows that same functionality implemented on a MILS-based architecture. The projects show how transparent communication security policies can be implemented with existing technologies and without any modifications to the operating system kernels.
Keywords :
Internet; Unix; data integrity; data privacy; distributed object management; grid computing; operating system kernels; telecommunication security; transport protocols; CORBA; Internet; MILS architecture; Unix TCP/IP network; communication security; data isolation; data sanitation; filters; global information grid; integrity operating system; multiple independent levels of security architecture; multiple isolated execution environments; multiple workstations; operating system kernels; protocol mediators; separation kernel; software mediators; transparent channel control; unbounded computing networks; wrappers; Communication system control; Communication system security; Computer architecture; Computer networks; Data security; Grid computing; IP networks; Information security; Kernel; Operating systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
Print_ISBN :
0-7803-9290-6
Type :
conf
DOI :
10.1109/IAW.2005.1495953
Filename :
1495953
Link To Document :
بازگشت