【24h】

Attestation-based Policy Enforcement for Remote Access

机译:基于证明的远程访问策略实施

获取原文
获取原文并翻译 | 示例

摘要

Intranet access has become an essential function for corporate users. At the same time, corporation's security administrators have little ability to control access to corporate data once it is released to remote clients. At present, no confidentiality or integrity guarantees about the remote access clients are made, so it is possible that an attacker may have compromised a client process and is now downloading or modifying corporate data. Even though we have corporate-wide access control over remote users, the access control approach is currently insufficient to stop these malicious processes. We have designed and implemented a novel system that empowers corporations to verify client integrity properties and establish trust upon the client policy enforcement before allowing clients (remote) access to corporate Intranet services. Client integrity is measured using a Trusted Platform Module (TPM), a new security technology that is becoming broadly available on client systems, and our system uses these measurements for access policy decisions enforced upon the client's processes. We have implemented a Linux 2.6 prototype system that utilizes the TPM measurement and attestation, existing Linux network control (Netfilter), and existing corporate policy management tools in the Tivoli Access Manager to control remote client access to corporate data. This prototype illustrates that our solution integrates seamlessly into scalable corporate policy management and introduces only a minor performance overhead.
机译:内联网访问已成为企业用户的基本功能。同时,一旦公司数据发布到远程客户端,公司的安全管理员几乎无法控制对公司数据的访问。目前,尚不保证有关远程访问客户端的机密性或完整性,因此攻击者有可能破坏了客户端进程,现在正在下载或修改公司数据。即使我们拥有对远程用户的整个企业范围的访问控制,但访问控制方法当前仍不足以阻止这些恶意进程。我们设计并实现了一个新颖的系统,该系统使公司能够验证客户端完整性属性,并在允许客户端(远程)访问企业内部网服务之前,对客户端策略的执行建立信任。客户端完整性是使用可信平台模块(TPM)来衡量的,TPM是一种在客户端系统上广泛可用的新安全技术,我们的系统将这些度量用于根据客户端流程执行的访问策略决策。我们已经实现了Linux 2.6原型系统,该系统利用TPM测量和证明,现有Linux网络控制(Netfilter)和Tivoli Access Manager中现有的公司策略管理工具来控制对公司数据的远程客户机访问。此原型说明我们的解决方案无缝集成到可伸缩的公司策略管理中,并且仅引入了较小的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号