Publication No 33593
|
Author(s)
|
Sailer, R.; Kabatnik, M.*
|
Title
|
History Based Distributed Filtering - A Tagging Approach to Network-Level Access Control
|
Topics
|
Network Security
|
Methods
|
Systems Engineering; Network Planning
|
Keywords
|
SIGNALLING; SECURITY; NETWORK SECURITY
|
Abstract
|
This contribution discusses a network-level access control technique that applies the non-discretionary access control model to individual data packets that are exchanged between hosts or subnets. The proposed technique examines incoming data's integrity properties to prevent applications within a node or subnetwork from so called subversive channels. It checks outgoing data's secrecy requirements before transmission. Security labels are used to identify data packets as members of different categories and security levels. Additional tags store context information to validate the trustworthiness of a packet's content. Labels and tags of a data packet reflect events that may be relevant to access control throughout its life. As opposed to stateful filtering, which is based on the history of a flow of packets, our approach works on the history of an individual packet. Any state information is part of the packet rather than stored in all the nodes inspecting the packet; i.e. nodes do not need to create and maintain state information.
|
Year
|
2000
|
Reference entry
|
Sailer, R.; Kabatnik, M.
History Based Distributed Filtering - A Tagging Approach to Network-Level Access Control
Proceedings of the 16th Annual Computer Security Applications Conference (ACSAC 2000), New Orleans, December 2000, pp. 373-382
|
BibTex file
|
Download [BIBTEX]
|
Full Text
|
No full text available online. To obtain a copy of the publication, please mail to
mail@ikr.uni-stuttgart.de and refer to "Publication number 33593".
|