首页> 外文会议> >The STRONGMAN architecture
【24h】

The STRONGMAN architecture

机译:STRONGMAN架构

获取原文

摘要

The design principle of restricting local autonomy only where necessary for global robustness has led to a scalable Internet. Unfortunately, this scalability and capacity for distributed control has not been achieved in the mechanisms for specifying and enforcing security policies. This shortcoming must be overcome if end-to-end security mechanisms (such as IPsec or TLS) are to ever replace solutions of short-term convenience such as firewalls. The STRONGMAN (for Scalable Trust Of Next Generation Management) system offers three new approaches to scalability, applying the principle of local policy enforcement complying with global security policies. First is the use of a compliance checker to provide great local autonomy within the constraints of a global security policy. Second is a mechanism to compose policy rules into a coherent enforceable set, e.g. at the boundaries of two locally autonomous application domains. Third is the "lazy instantiation" of policies to reduce the amount of state that enforcement points need to maintain. We demonstrate the use of these approaches in the design, implementation, and measurements of a distributed firewall. Our experiments show that, under certain circumstances, performance can improve over the traditional-firewall approach.
机译:仅在全球稳健性必要时限制当地自主权的设计原则导致了可扩展的互联网。遗憾的是,在指定和执行安全策略的机制中尚未实现这种可扩展性和分布式控制能力。如果端到端安全机制(例如IPSec或TLS)替换防火墙等短期方便的解决方案,则必须克服此缺点。强大的人(用于下一代管理的可扩展信任)系统提供了三种可扩展性的新方法,应用了当地策略执法的原则遵守全球安全政策。首先是在全球安全策略的约束中使用合规检查员在全球安全策略的限制范围内提供良好的本地自主权。其次是将政策规则融入连贯的可执行集合的机制,例如,在两个局部自主应用域的界限。三是政策的“懒惰实例化”,以减少执法点需要维持的国家金额。我们展示了在分布式防火墙的设计,实现和测量中使用这些方法。我们的实验表明,在某些情况下,性能可以改善传统防火墙方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号