• DocumentCode
    2822488
  • Title

    Layering boundary protections: an experiment in information assurance

  • Author

    Bensinger, L.A. ; Johnson, Dale M.

  • Author_Institution
    NAI Labs., USA
  • fYear
    2000
  • fDate
    36861
  • Firstpage
    60
  • Lastpage
    66
  • Abstract
    The DARPA Information Assurance Program has the aim of developing and executing experiments that test specific hypotheses about defense in depth and dynamic defense capabilities. This paper describes the development and execution of an experiment in layering. The basic hypothesis was that layers of defense, when added in a careful and systematic way to a base system lead to increased protection against attacks on the system. For the particular experiment, a mission and broad policy were defined and a base system was developed to support the mission and the policy. The boundary controller for the system was designed and developed as a series of layers; these elements became the main focus of experimentation on layering. The results tended to confirm the experimental hypothesis that layers have a cumulative effect on protection against outside attacks. However, there are often other opportunities for attackers to go around the layers or avoid them altogether. A broader methodological result was that the entire process of developing experiments needs to be carefully thought through. In addition, the experimental data resulting from this experiment provide only a limited corroboration for the given experimental hypothesis
  • Keywords
    client-server systems; data privacy; security of data; DARPA Information Assurance Program; attack protection; boundary protection layering; client server system; data confidentiality; data security; experiment; Availability; Control systems; Focusing; Information security; Laboratories; Mechanical factors; Protection; Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications, 2000. ACSAC '00. 16th Annual Conference
  • Conference_Location
    New Orleans, LA
  • Print_ISBN
    0-7695-0859-6
  • Type

    conf

  • DOI
    10.1109/ACSAC.2000.898858
  • Filename
    898858