DocumentCode :
3396396
Title :
Dynamic authorization and intrusion response in distributed systems
Author :
Ryutov, Tatyana ; Neuman, Clifford ; Kim, Dongho
Volume :
1
fYear :
2003
fDate :
22-24 April 2003
Firstpage :
50
Abstract :
This paper presents an authorization framework for supporting fine-grained access control policies enhanced with light-weight intrusion/misuse detectors and response capabilities. The framework intercepts and analyzes access requests and dynamically adjusts security policies to prevent attackers from exploiting application level vulnerabilities. We present a practical, flexible implementation of the framework based on the Generic Authorization and Access Control API (GAA-API) that provides dynamic authorization and intrusion response capabilities for many applications. To evaluate our approach, we integrated the API with several applications, including the Apache Web server, sshd and FreeS/WAN IPsec for Linux. This paper demonstrates the integration of the GAA-API into ssh daemon. By integrating the GAA-API into the sshd, the ssh server can support fine-grained authorization policies, dynamic policy update, and application level intrusion detection and response. The server can also enforce policies with additional functionality, e.g., time- and location-based controls. Our experiments showed that the required integration effort was moderate, and that the performance impact on the ssh server was reasonable.
Keywords :
Internet; application program interfaces; authorisation; Apache Web server; FreeS/WAN IPsec for Linux; Generic Authorization and Access Control API; access requests; application level intrusion detection; application level intrusion response; application level vulnerabilities; distributed systems; dynamic authorization; dynamic policy update; dynamic security policy adjustment; fine-grained access control policies; fine-grained authorization policies; light-weight intrusion detectors; light-weight misuse detectors; location based controls; response capabilities; ssh daemon; ssh server; sshd; time based controls; Access control; Authorization; Computer crime; Information security; Intrusion detection; Linux; Permission; Web and internet services; Web server; Wide area networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
DARPA Information Survivability Conference and Exposition, 2003. Proceedings
Print_ISBN :
0-7695-1897-4
Type :
conf
DOI :
10.1109/DISCEX.2003.1194872
Filename :
1194872
Link To Document :
بازگشت