DocumentCode
1925017
Title
Managing network security policies in tactical MANETs using DRAMA
Author
Cheng, Yuu-Heng ; Ghosh, Abhrajit ; Chadha, Ritu ; Gary, M.L. ; Wolberg, Michelle ; Chiang, C. Jason ; Hadynski, Gregory
Author_Institution
Knowledge-Based Syst., Telcordia, Piscataway, NJ, USA
fYear
2010
fDate
Oct. 31 2010-Nov. 3 2010
Firstpage
960
Lastpage
964
Abstract
Military networks are required to adapt their access control policies to the Information Operations Condition (INFOCON) levels to minimize the impact of potential malicious activities. Such adaptations must be automated to the extent possible, consistent with mission requirements, and applied network-wide. In this paper, we present a Policy-Based Network Security (PBNS) management approach for tactical MANETs. This approach leverages the DRAMA policy based network management system and the Smart Firewall system to meet the above requirement. It allows administrators to specify low-level network access control policies for each INFOCON level using high-level policies (adapted from the Smart Firewalls approach). The high-level policies are securely distributed to all the policy decision points in the network, which evaluate and enforce policies in a distributed manner. As a consequence of enforcing policies in response to INFOCON level changes, appropriate access control policies will be derived and applied to local firewall devices without human intervention. Thus, operator burden can be significantly reduced and inadvertent errors can be avoided.
Keywords
authorisation; military communication; mobile ad hoc networks; telecommunication network management; telecommunication security; DRAMA policy; INFOCON; PBNS management; Smart Firewall system; dynamic re-addressing and management for the army; information operation condition; low-level network access control policy; military networks; mobile ad hoc networks; policy-based network security management; tactical MANET; Access control; Ad hoc networks; Fires; Intrusion detection; Mobile computing; Web services; MANET; firewalls; network access control; network operations; policy-based management; security;
fLanguage
English
Publisher
ieee
Conference_Titel
MILITARY COMMUNICATIONS CONFERENCE, 2010 - MILCOM 2010
Conference_Location
San Jose, CA
ISSN
2155-7578
Print_ISBN
978-1-4244-8178-1
Type
conf
DOI
10.1109/MILCOM.2010.5679579
Filename
5679579
Link To Document