• DocumentCode
    1937660
  • Title

    Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach

  • Author

    Blanc, Mathieu ; Briffaur, J. ; Lalande, Jean-François ; Toinard, Christian

  • Author_Institution
    Commissariat a l´´Energie Atomique, Bruyeres-le-Chatel
  • fYear
    2006
  • fDate
    5-7 June 2006
  • Lastpage
    156
  • Abstract
    This paper presents a new framework based on a meta-policy linked to a new intrusion detection approach. It deploys a MAC kernel within a distributed system while guaranteeing the consistency of the security policy, preventing any accidental or malicious update of the local policies of each host. Access control decisions are resolved locally in accordance with a meta-policy. At the same time, the framework allows the evolution of the distributed policy without any network communication, and also guarantees that it satisfies the global security properties defined in the meta-policy. The combined policy and IDS approach relies on trusted operating systems integrating MAC and RBAC. The proposed architecture controls a wider set of attacks and provides increased fault-tolerance, compared to other existing distributed access control approaches and policy-based IDS techniques. Details are given about languages used for the meta-policy, and implementation of the framework
  • Keywords
    authorisation; distributed processing; MAC kernel; MAC policies; RBAC; access control decisions; distributed access control; distributed policy; distributed system; fault tolerance; global security properties; intrusion detection; metapolicy approach; network communication; security policy; trusted operating systems; Access control; Communication system control; Communication system security; Control systems; Distributed control; Fault tolerance; Intrusion detection; Kernel; Operating systems; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2006. Policy 2006. Seventh IEEE International Workshop on
  • Conference_Location
    London, Ont.
  • Print_ISBN
    0-7695-2598-9
  • Type

    conf

  • DOI
    10.1109/POLICY.2006.15
  • Filename
    1631168