首页> 外文学位 >Architectural support for security management in enterprise networks.
【24h】

Architectural support for security management in enterprise networks.

机译:企业网络中安全管理的体系结构支持。

获取原文
获取原文并翻译 | 示例

摘要

Enterprise networks are often large, run a wide variety of applications and protocols, and operate under strict reliability constraints; thus, they represent a challenging environment for security management. Security policies in todays enterprise are typically enforced by regulating connectivity with a combination of complex routing and bridging policies along with various interdiction mechanisms such as ACLs, packet filters, and middleboxes that attempt to retrofit access control onto an otherwise permissive network architecture. This leads to networks that are inflexible, fragile, difficult to manage, and still riddled with security problems.; This thesis presents a principled approach to network redesign that creates more secure and manageable networks. We propose a new network architecture in which a global security policy defines all connectivity. The policy is declared at a logically centralized Controller and then enforced directly at each switch. All communication must first obtain permission from the Controller before being forwarded by any of the network switches. The Controller manages the policy namespace and performs all routing and access control decisions, while the switches are reduced to simple forwarding engines that enforce the Controller's decisions.; We present an idealized instantiation of the network architecture called SANE. In SANE, the Controller grants permission to requesting flows by handing out capabilities (encrypted source routes). SANE switches will only forward a packet if it contains a valid capability between the link and network headers. SANE thus introduces a new, low-level protection layer that defines all connectivity on the network.; SANE would require a fork-lift replacement of an enterprise's entire networking infrastructure and changes to all the end-hosts. While this might be suitable in some cases, it is clearly a significant impediment to widespread adoption. To address this, we present Ethane a deployable instantiation of our architecture. Ethane does not require modification to end-hosts and can be incrementally deployed within an existing network. Instead of handing out capabilities, permission is granted by explicitly setting up flows at each switch. We have implemented Ethane in both hardware and software, supporting both wired and wireless hosts. We describe our experience managing an operational Ethane network of over 300 hosts.
机译:企业网络通常很大,运行各种应用程序和协议,并且在严格的可靠性约束下运行;因此,它们代表了一个充满挑战的安全管理环境。当今企业中的安全策略通常是通过结合复杂的路由和桥接策略以及各种拦截机制(例如ACL,数据包筛选器和中间盒)的组合来调节连接性,这些机制试图将访问控制改造为其他允许的网络体系结构。这导致网络僵化,脆弱,难以管理并且仍然充满安全问题。本文提出了一种原则上的网络重新设计方法,该方法可以创建更安全和可管理的网络。我们提出了一种新的网络体系结构,其中全局安全策略定义了所有连接。该策略在逻辑上集中的Controller上声明,然后在每个交换机上直接执行。所有通信在被任何网络交换机转发之前,必须首先获得控制器的许可。 Controller管理策略名称空间并执行所有路由和访问控制决策,而将交换机简化为执行Controller决策的简单转发引擎。我们提出了称为SANE的网络架构的理想化实例。在SANE中,控制器通过分发功能(加密的源路由)来授予请求流的权限。如果SANE交换机在链接和网络头之间包含有效功能,则仅转发该数据包。因此,SANE引入了一个新的低层保护层,该层定义了网络上的所有连接。 SANE将需要用叉车更换企业的整个网络基础架构,并更改所有终端主机。尽管这在某些情况下可能是合适的,但显然这是广泛采用的重大障碍。为了解决这个问题,我们向Ethane展示了我们架构的可部署实例。 Ethane不需要修改终端主机,可以在现有网络中增量部署。除了分发功能外,还通过在每个交换机上显式设置流来授予权限。我们已经在硬件和软件上实现了Ethane,同时支持有线和无线主机。我们描述了管理超过300个主机的Ethane运行网络的经验。

著录项

  • 作者

    Casado, Martin.;

  • 作者单位

    Stanford University.;

  • 授予单位 Stanford University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2007
  • 页码 95 p.
  • 总页数 95
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号