• DocumentCode
    2899295
  • Title

    A Trusted Integrity Measurement Architecture for Securing Enterprise Network

  • Author

    Liu, Tong ; Agrawal, Prathima

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Auburn Univ., Auburn, AL, USA
  • fYear
    2011
  • fDate
    16-18 Nov. 2011
  • Firstpage
    726
  • Lastpage
    731
  • Abstract
    The threat landscape continues to evolve, with increasingly complex attacks directed at the corporate network to achieve malicious goals. Enterprise networks build their first line of defense with firewalls and virtual private network (VPN) gateways. However, this kind of defense can be easily circumvented. It is possible that an attacker may have compromised a client process and gain privilege of the client computer. Even though we have corporate-wide access control, the access control approach is currently insufficient to stop these malicious processes. To better defend enterprise network, this paper proposed a novel system that empowers the corporate networks to verify client integrity properties based on our trusted measurement architecture. When the critical system configuration is changed, the trusted platform module (TPM) attestation mechanism is called to inform security agent about the trusted measurement values. Once the verification process fails, the client will be excluded from the network and notification to a super security agent will be sent. The system performance is also illustrated in this paper.
  • Keywords
    authorisation; business communication; computer network security; data integrity; intranets; trusted computing; virtual private networks; client computer; client integrity property; client process; complex attack; corporate network; corporate-wide access control; critical system configuration; enterprise network security; firewalls; malicious process; security agent; threat landscape; trusted integrity measurement architecture; trusted measurement architecture; trusted measurement value; trusted platform module attestation mechanism; virtual private network gateway; Computers; Kernel; Linux; Security; Servers; Software measurement; integrity; security agent; trusted platform module;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
  • Conference_Location
    Changsha
  • Print_ISBN
    978-1-4577-2135-9
  • Type

    conf

  • DOI
    10.1109/TrustCom.2011.94
  • Filename
    6120887