• DocumentCode
    3003281
  • Title

    Arachne: Integrated Enterprise Security Management

  • Author

    Burnside, Matthew ; Keromytis, Angelos D.

  • fYear
    2007
  • fDate
    20-22 June 2007
  • Firstpage
    214
  • Lastpage
    220
  • Abstract
    Security policies are a key component in protecting enterprise networks. There are many defensive options available to these policies, but current mechanically-enforced security policies are limited to traditional admission-based access control. There are defensive capabilities available that include logging, firewalls, honeypots, rollback/recovery, and intrusion detection systems, but policy enforcement is essentially limited to allow/deny semantics. Furthermore, access-control mechanisms operate independently on each service, which often leads to inconsistent or incorrect application of the intended system-wide policy. To begin to solve these problems, we propose a new system for defense-in-depth using global security policies. Under a global security policy, every policy decision is made with near-global knowledge, and re-evaluated as global knowledge changes, given an initial configuration provided by the administrator. Using a variety of actuators, we make the full array of defensive capabilities available to the global policy. We outline our proposal for enterprise-wide security policies, explore the design space, and discuss Arachne, our prototype implementation.
  • Keywords
    access control; security of data; telecommunication security; Arachne; admission-based access control; enterprise networks; enterprise-wide security; global knowledge; global security policies; integrated enterprise security management; policy decision; system-wide policy; Data security; Databases; IP networks; Information security; Intrusion detection; Modems; Prototypes; Space exploration; Tellurium; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
  • Conference_Location
    West Point, NY
  • Print_ISBN
    1-4244-1304-4
  • Electronic_ISBN
    1-4244-1304-4
  • Type

    conf

  • DOI
    10.1109/IAW.2007.381935
  • Filename
    4267563