ACM Home Page
Please provide us with feedback. Feedback
Asynchronous policy evaluation and enforcement
Full text PdfPdf (97 KB)
Source
Conference on Computer and Communications Security archive
Proceedings of the 2nd ACM workshop on Computer security architectures table of contents
Alexandria, Virginia, USA
SESSION: Network security architecture table of contents
Pages 45-50  
Year of Publication: 2008
ISBN:978-1-60558-300-6
Authors
Matthew Burnside  Columbia University, New York, NY, USA
Angelos D. Keromytis  Columbia University, New York, NY, USA
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 7,   Downloads (12 Months): 63,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1456508.1456517
What is a DOI?

ABSTRACT

Evaluating and enforcing policies in large-scale networks is one of the most challenging and significant problems facing the network security community today. Current solutions are limited by an out-of-date allow/deny paradigm, and policies are evaluated synchronously and independently at each service. This makes it difficult to detect or defend against multi-stage attacks, or attacks which begin as innocent requests and then later exhibit malicious behavior in the same context. In this paper we describe Arachne, a prototype for asynchronous policy evaluation. We evaluate the system by testing it against pre-recorded traffic containing known and unknown attacks and show that it is capable of processing events at more than 10x the required rate for a deployed, heavily-used network.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Coppermine Photo Gallery. http://www.coppermine-gallery.net.
 
2
Y. Bartal, A. Mayer, K. Nissim, and A. Wool. Firmato: a novel firewall management toolkit. In Proceedings of the 1999 IEEE Symposium on Security and Privacy, pages 17--31, May 1999.
 
3
 
4
Matthew Burnside and Angelos Keromytis. Arachne: Integrated enterprise security management. In 8th Annual IEEE SMC Information Assurance Workshop, pages 214--220, 2007.
 
5
 
6
P. Calhoun, A. Rubens, H. Akhtar, and E. Guttman. DIAMETER Base Protocol. Internet Draft, Internet Engineering Task Force, December 1999. Work in progress.
 
7
 
8
Rahim Choudhary. A Policy Based Architecture for NSA RAdAC Model. In Proceedings of 6th IEEE Workshop on Information Assurance and Security, United States Military Academy, West Point, NY, June 2005.
 
9
Rahim Choudhary. Compound Identity Measure: A New Concept in Information Assurance. In Proceedings of 7th IEEE Workshop on Information Assurance and Security, United States Military Academy, West Point, NY, June 2006.
 
10
M. Damianou. A Policy Framework for Management of Distributed Systems. PhD thesis, 2002.
11
 
12
G. S. Graham and P. J. Denning. Protection: Principles and Practices. In Proceedings of the AFIPS Spring Joint Computer Conference, pages 417--429, 1972.
 
13
Stephen Kent, Charles Lynn, and Kareo Seo. Secure border gateway protocol (secure-bgp). 18(4):582--592, April 2000.
 
14
A. D. Keromytis, S. Ioannidis, M. B. Greenwald, and J. M. Smith. The STRONGMAN Architecture. In Proceedings of the 3rd DARPA Information Survivability Conference and Exposition (DISCEX III), pages 178--188, April 2003.
 
15
B. W. Lampson. Protection. In Proceedings of the 5th Princeton Symposium on Information Sciences and Systems, pages 473--443, March 1971.
16
 
17
Robert W. McGraw. Securing Content in the Department of Defense's Global Information Grid. In Secure Knowledge Management Workshop, State University of New York, Buffalo, NY, September 2004.
18
 
19
Peng Ning, Yun Cui, and Douglas S. Reeves. Analyzing intensive intrusion alerts via correlation. In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID 2002), Zurich, Switzerland, October 2002.
20
 
21
qaaz. Linux vmsplice Local Root Exploit. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464953, February 2008.
 
22
 
23
J. Schnizlein, J. Strassner, M. Scherling, B. Quinn, S. Herzog, A. Huynh, M. Carlson, J. Perry, and S. Waldbusser. Terminology for Policy-Based Management. Request for Comments (Proposed Standard) 3198, Internet Engineering Task Force, November 2001.
 
24
 
25
Janek Vind. Remote Shell Command Execution in Coppermine 1.4.14. http://www.waraxe.us/advisory-65.html, January 2008.

Collaborative Colleagues:
Matthew Burnside: colleagues
Angelos D. Keromytis: colleagues