首页> 外文会议>International Conference on Network and System Security >DIPLOMA: Distributed Policy Enforcement Architecture for MANETs
【24h】

DIPLOMA: Distributed Policy Enforcement Architecture for MANETs

机译:文凭:船只的分布式策略执法架构

获取原文

摘要

Lack of well-defined defense perimeter in MANETs prevents the use traditional firewalls, and requires the security to be implemented in a distributed manner. We recently introduced a novel deny-by-default distributed security policy enforcement architecture for MANETs by harnessing and extending the concept of {it network capabilities}. The {it deny-by-default} principle allows compromised nodes to access only authorized services, limiting their ability to disrupt or even interfere with end-to-end connectivity and nodes beyond their local communication radius. The enforcement of policies is done hop-by-hop, in a distributed manner. In this paper, we present the implementation of this architecture, called DIPLOMA, on Linux. Our implementation works at the network layer, and does not require any changes to existing applications. We identify the bottlenecks of the original architecture and propose improvements, including a signature optimization, so that it works well in practice. We present the results of evaluating the architecture in a realistic MANET testbed Orbit. The results show that the architecture incurs minimal overhead in throughput, latency and jitter. We also show that the system protects network bandwidth and the end-hosts in the presence of attackers. To that end, we identify ways of creating multi-hop topologies in indoor environments so that a bad node cannot interfere with every other node. We also show that existing applications are not impacted by the new architecture, achieving good performance.
机译:漫手缺乏明确的防御周边防止使用传统防火墙,并要求以分布式方式实现安全性。我们最近通过利用和扩展{IT网络能力}的概念来引入了疯狂逐默认的分布式安全策略强制执行架构。 {IT拒绝默认默认}原则允许受损的节点仅访问仅访问授权服务,限制其破坏甚至会干扰其本地通信半径之外的端到端连接和节点的能力。策略的执行是以分布式方式完成的。在本文中,我们介绍了这种架构,称为文凭,在Linux上。我们的实现在网络层的工作,不需要对现有应用程序的任何更改。我们确定原始架构的瓶颈,并提出改进,包括签名优化,以便在实践中运行良好。我们介绍了在现实枪门轨道中评估架构的结果。结果表明,该架构在吞吐量,延迟和抖动中突出了最小的开销。我们还表明系统在存在攻击者的情况下保护网络带宽和最终主机。为此,我们确定了在室内环境中创建多跳拓扑的方法,以便错误的节点无法干扰每个其他节点。我们还表明现有申请不会受到新架构的影响,实现良好的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号