首页> 外文会议>IFIP-TC 6/TC 11 international conference on communications and multimedia security >A Framework for Enforcing User-Based Authorization Policies on Packet Filter Firewalls
【24h】

A Framework for Enforcing User-Based Authorization Policies on Packet Filter Firewalls

机译:在数据包筛选器防火墙上实施基于用户的授权策略的框架

获取原文

摘要

Packet filter firewalls are fundamental elements to prevent unauthorized traffic to reach protected networks or hosts. However, they have to take decisions about packets based on their contents, and currently packets do not contain any information about the entity responsible for its generation. In this paper we propose a framework that tackle this problem. The framework adds extra information to packets, which enables a firewall to authenticate its origin and to get an identity attribute for discriminating the entity responsible for the packet, upon which an access control policy can be implemented. This framework uses trusted third party services for authenticating people and providing related identity attributes for firewalls. For a proof of concept we implemented a prototype in Linux machines using iptables and personal identity smartcards.
机译:数据包筛选器防火墙是防止未经授权的流量到达受保护的网络或主机的基本元素。但是,它们必须根据其内容来决定有关数据包的决定,并且当前数据包不包含有关负责其生成的实体的任何信息。在本文中,我们提出了一个解决此问题的框架。该框架向数据包添加了额外的信息,从而使防火墙能够验证其起源并获得用于区分负责该数据包的实体的身份属性,可以在该属性上实现访问控制策略。该框架使用受信任的第三方服务来对人员进行身份验证并为防火墙提供相关的身份属性。为了进行概念验证,我们在Linux机器上使用iptables和个人身份智能卡实现了原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号