Title :
Grid of Security: A New Approach of the Network Security
Author :
Flauzac, Olivier ; Nolot, Florent ; Rabat, Cyril ; Steffenel, Luiz-Angelo
Author_Institution :
CReSTIC SysCom Team, Univ. of Reims Champagne-Ardenne, Reims, France
Abstract :
Network security is in a daily evolving domain. Every day, new attacks, virus or intrusion techniques are released. Hence, network devices, enterprise servers or personal computers are potential targets of these attacks. Current security solutions like firewalls, intrusion detection systems (IDS) and virtual private networks (VPN) are centralized solutions which rely mostly on the analyze of inbound network connections. This approach notably forgets the effects of a rogue station, whose communications cannot be easily controlled unless the administrators establish a global authentication policy using methods like 802.1x to control all network communications among each device. To the best of our knowledge, a distributed and easily manageable solution for the global security of an enterprise network does not exist. In this paper, we present a new approach to deploy a distributed security solution where communication between each device can be control in a collaborative manner. Indeed, each device has its own security rules, who can be shared and improved through exchanges with others devices. With this new approach, called grid of security, a community of devices ensures that a device is trustworthy and that communications between devices progress in respect of the control of the system policies. To support this approach, we present a new communication model that helps structuring the distribution of security services among the devices. Like this, we can secure both ad-hoc, local-area or enterprise networks in a decentralized manner, preventing the risk of a security breach in the case of a failure.
Keywords :
grid computing; middleware; peer-to-peer computing; security of data; authentication policy; distributed security solution; firewalls; grid of security; intrusion detection systems; network security; virtual private networks; Authentication; Collaboration; Communication system control; Communication system security; Control systems; Intrusion detection; Knowledge management; Microcomputers; Network servers; Virtual private networks; distributed communication; grid design; security architecture;
Conference_Titel :
Network and System Security, 2009. NSS '09. Third International Conference on
Conference_Location :
Gold Coast, QLD
Print_ISBN :
978-1-4244-5087-9
Electronic_ISBN :
978-0-7695-3838-9
DOI :
10.1109/NSS.2009.53