• DocumentCode
    3346265
  • Title

    Managing access and usage controls in SNMP

  • Author

    Barka, E. ; Sallabi, F. ; Hosani, A.

  • Author_Institution
    Coll. of Inf. Technol., UAE Univ., Al Ain, United Arab Emirates
  • fYear
    2012
  • fDate
    11-13 Jan. 2012
  • Firstpage
    41
  • Lastpage
    47
  • Abstract
    Simple Network Management Protocol “SNMP”, which is a component of the Internet Protocol Suite, is the most widely-used protocol in network management systems today. It is used to monitor network-attached devices such as routers, switches, Servers, workstations, printers, etc., for conditions that warrant administrative attention. In its initial versions, SNMPv1 and SNMPv2, SNMP was criticized for its lack of security, however, in its latest version, SNMPv3, it added important security features such as confidentiality, message integrity, authentication, and access control. In this paper we analyze the current approach, used by SNMP for providing access control, and we present new architecture that implements a new type of access control, called Usage Control (UCON), to better-control the access to the SNMP-managed environment at: pre-connection, during connection, and post connection. We believe that our proposed solution will enable owners of the SNMP-managed network to control who can access the system objects “i.e. the MIBs”, to control the activities of both the manager and the agent entities, and to help set some parameters to determine whether a communication between the agent and the manager can continue or should terminate.
  • Keywords
    IP networks; access control; protocols; telecommunication network management; Internet protocol; SNMP; SNMPv1; SNMPv2; SNMPv3; access controls; authentication; message integrity; network management systems; simple network management protocol; usage controls; Authentication; Authorization; Communities; Context; Monitoring; Servers; Access Control; SNMP; UCON; VBAC;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing, Communications and Applications Conference (ComComAp), 2012
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-1-4577-1717-8
  • Type

    conf

  • DOI
    10.1109/ComComAp.2012.6154000
  • Filename
    6154000