DocumentCode :
3003281
Title :
Arachne: Integrated Enterprise Security Management
Author :
Burnside, Matthew ; Keromytis, Angelos D.
fYear :
2007
fDate :
20-22 June 2007
Firstpage :
214
Lastpage :
220
Abstract :
Security policies are a key component in protecting enterprise networks. There are many defensive options available to these policies, but current mechanically-enforced security policies are limited to traditional admission-based access control. There are defensive capabilities available that include logging, firewalls, honeypots, rollback/recovery, and intrusion detection systems, but policy enforcement is essentially limited to allow/deny semantics. Furthermore, access-control mechanisms operate independently on each service, which often leads to inconsistent or incorrect application of the intended system-wide policy. To begin to solve these problems, we propose a new system for defense-in-depth using global security policies. Under a global security policy, every policy decision is made with near-global knowledge, and re-evaluated as global knowledge changes, given an initial configuration provided by the administrator. Using a variety of actuators, we make the full array of defensive capabilities available to the global policy. We outline our proposal for enterprise-wide security policies, explore the design space, and discuss Arachne, our prototype implementation.
Keywords :
access control; security of data; telecommunication security; Arachne; admission-based access control; enterprise networks; enterprise-wide security; global knowledge; global security policies; integrated enterprise security management; policy decision; system-wide policy; Data security; Databases; IP networks; Information security; Intrusion detection; Modems; Prototypes; Space exploration; Tellurium; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
Conference_Location :
West Point, NY
Print_ISBN :
1-4244-1304-4
Electronic_ISBN :
1-4244-1304-4
Type :
conf
DOI :
10.1109/IAW.2007.381935
Filename :
4267563
Link To Document :
بازگشت