Title :
Application level network access control system based on TNC architecture for enterprise network
Author :
Chen, Zhen ; Deng, Fa-Chao ; Luo, An-An ; Jiang, Xin ; Li, Guo-Dong ; Zhang, Run-hua ; Lin, Chuang
Author_Institution :
Dept. of Autom. & Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
Abstract :
Traditional NAC system in enterprise network is in coarse granularity (e.g. IP or MAC address) and lack of flexibility. Recently the demand in tight control of the enterprise network to defense the misuse and security issues become more and more urgent. Based on the TCG TNC standard, an application level network access control mechanism is proposed and implemented. With TNC client/server model in hand, a client is designed to enhance TNC client with the function of host flow controller (HFC), and intercepts each application network access request(ANAR) and transfer it to PDP server to authorize the access request. When a sensor (i.e. intrusion detection system) detects any malicious traffic, host flow controller and network flow controller can identify the application that origins this traffic by querying Metadata Access Point (MAP) server and block this application´s network access. A prototype system is implemented to demonstrate the design and can be used to defense the anomaly network behaviors. The prototype system demonstrates that the hosts, switches, firewalls and IDS can work together to detect, diagnose and protect enterprise network from the malicious applications attack initiated inside or outside of an enterprise network, quarantine unhealthy hosts and make the enterprise network more reliable and trustworthy.
Keywords :
Access control; Communication system traffic control; Control systems; Hybrid fiber coaxial cables; Intrusion detection; Network servers; Prototypes; Sensor systems and applications; Switches; Traffic control; Access Control; Application Level Access Control; Network Security; Trusted Network Connect;
Conference_Titel :
Wireless Communications, Networking and Information Security (WCNIS), 2010 IEEE International Conference on
Conference_Location :
Beijing, China
Print_ISBN :
978-1-4244-5850-9
DOI :
10.1109/WCINS.2010.5541863