首页> 外文会议>ACM symposium on access control models and technologies >Automated Management of Network Access Control from Design to Enforcement
【24h】

Automated Management of Network Access Control from Design to Enforcement

机译:自动管理网络访问控制从设计到执法

获取原文

摘要

Recent studies show that more than 65% of the network vulnerabilities are due to misconfigured network access control. Arbor Networks in their ISP survey shows that managing access control is the top challenge in ISP networks today, which creates major reachability and security violations such as unauthorized access/traffic, backdoors and increasing attack surface [1]. Access control exists in network devices such as routers, firewall and IPSec gateways and application-level such RBAC systems and authorization servers. The wide distribution of large number of access control configurations that usually exhibit different syntactic and semantic behavior in highly dynamic network environments creates real challenges for verifying, evaluating and enforcing access control policies. Thus, there is a pressing need for models and tools that allow for global end-to-end analysis of access control by integrating network and application-level access control in a single framework from design, verification and optimization to evaluation and deployment. These frameworks should also provide quantitative means to design and evaluate access control automatically and objectively [2, 3]. In addition, as security risk is dynamically changing in networks due to new threats or users' behavior, enabling proactive access control will play an important role in future network defense. In this talk, I will present the state-of-the-art and discuss future challenges of designing, verification and evaluation of access control policies.
机译:最近的研究表明,超过65%的网络漏洞是由于错误配置的网络访问控制。 arbor网络中的ISP调查显示,管理访问控制是ISP网络今天的最大挑战,它创造了主要的可达性和安全违规,例如未经授权的访问/流量,后门和增加攻击面[1]。访问控制存在于网络设备(如路由器,防火墙和IPSec网关)和应用程序级别此类RBAC系统和授权服务器中。大量访问控制配置的广泛分布通常在高度动态网络环境中表现出不同的句法和语义行为,为验证,评估和实施访问控制策略创造了真正的挑战。因此,通过在从设计,验证和优化到评估和部署的单一框架中,可以通过将网络和应用程序级访问控制集成网络和应用程序级访问控制来实现对访问控制的全局端到端分析的模型和工具。这些框架还应提供定量手段来自动设计和评估访问控制[2,3]。此外,由于安全风险由于新的威胁或用户的行为而在网络中动态地变化,因此能够实现主动访问控制将在未来的网络防御中发挥重要作用。在这次谈判中,我将提出最先进的,并讨论访问控制政策的设计,验证和评估的未来挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号