DocumentCode
3003281
Title
Arachne: Integrated Enterprise Security Management
Author
Burnside, Matthew ; Keromytis, Angelos D.
fYear
2007
fDate
20-22 June 2007
Firstpage
214
Lastpage
220
Abstract
Security policies are a key component in protecting enterprise networks. There are many defensive options available to these policies, but current mechanically-enforced security policies are limited to traditional admission-based access control. There are defensive capabilities available that include logging, firewalls, honeypots, rollback/recovery, and intrusion detection systems, but policy enforcement is essentially limited to allow/deny semantics. Furthermore, access-control mechanisms operate independently on each service, which often leads to inconsistent or incorrect application of the intended system-wide policy. To begin to solve these problems, we propose a new system for defense-in-depth using global security policies. Under a global security policy, every policy decision is made with near-global knowledge, and re-evaluated as global knowledge changes, given an initial configuration provided by the administrator. Using a variety of actuators, we make the full array of defensive capabilities available to the global policy. We outline our proposal for enterprise-wide security policies, explore the design space, and discuss Arachne, our prototype implementation.
Keywords
access control; security of data; telecommunication security; Arachne; admission-based access control; enterprise networks; enterprise-wide security; global knowledge; global security policies; integrated enterprise security management; policy decision; system-wide policy; Data security; Databases; IP networks; Information security; Intrusion detection; Modems; Prototypes; Space exploration; Tellurium; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
Conference_Location
West Point, NY
Print_ISBN
1-4244-1304-4
Electronic_ISBN
1-4244-1304-4
Type
conf
DOI
10.1109/IAW.2007.381935
Filename
4267563
Link To Document