Title :
Defeating the insider threat via autonomic network capabilities
Author :
Sibai, Faisal M. ; Menascé, Daniel A.
Author_Institution :
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
Abstract :
There has been a constant growing security concern on insider attacks on network accessible computer systems. Users with power credentials can do almost anything they want with the systems they own with very little control or oversight. Most breaches occurring nowadays by power users are considered legitimate access and not necessarily intrusions. Developing a solution for such a problem is challenging because power users need flexible requirements to administer or maintain their systems. The increased usage of virtual environments, virtual systems, teleworking, and remote usage has made network access the preferred method for system administration. This paper presents (1) the Autonomic Violation Prevention System (AVPS), a framework that provides a solution to this problem and meet the above mentioned challenges, and (2) a proof-of-concept prototype that embeds self-protection capabilities into traditional Network Intrusion Prevention Systems (NIPS). AVPS focuses on self-protection against security policy violations instead of malware, vulnerability, or exploit intrusions. AVPS heavily enforces separation of duties, promotes scalability, ease of use and manageability. The proof-of-concept prototype uses Snort in-line NIPS with our own customizations.
Keywords :
authorisation; computer network security; fault tolerant computing; autonomic network capability; autonomic violation prevention system; network accessible computer system; network intrusion prevention system; proof of concept prototype; security policy; self protection capability; system administration; teleworking; virtual environment; virtual system; Access control; Inspection; Malware; Payloads; Scalability; Servers;
Conference_Titel :
Communication Systems and Networks (COMSNETS), 2011 Third International Conference on
Conference_Location :
Bangalore
Print_ISBN :
978-1-4244-8952-7
Electronic_ISBN :
978-1-4244-8951-0
DOI :
10.1109/COMSNETS.2011.5716431