Aggregating and deploying network access control policies

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The existence of errors or inconsistencies in the configuration of security components, such as filtering routers and/or firewalls, may lead to weak access control policies -potentially easy to be evaded by unauthorized parties. We present in this paper a proposal to create, manage, and deploy consistent policies in those components in an efficient way. To do so, we combine two main approaches. The first approach is the use of an aggregation mechanism that yields consistent configurations or signals inconsistencies. Through this mechanism we can fold existing policies of a given system and create a consistent and global set of access control rules - easy to maintain and manage by using a single syntax. The second approach is the use of a refinement mechanism that guarantees the proper deployment of such a global set of rules into the system, yet free of inconsistencies.

Original languageEnglish
Title of host publicationProceedings - The Second International Conference on Availability, Reliability and Security, ARES 2007
PublisherIEEE Computer Society
Pages532-539
Number of pages8
ISBN (Print)0769527752, 9780769527758
DOIs
Publication statusPublished - 1 Jan 2007
Externally publishedYes
Event2nd International Conference on Availability, Reliability and Security, ARES 2007 - Vienna, Austria
Duration: 10 Apr 200713 Apr 2007

Publication series

NameProceedings - Second International Conference on Availability, Reliability and Security, ARES 2007

Conference

Conference2nd International Conference on Availability, Reliability and Security, ARES 2007
Country/TerritoryAustria
CityVienna
Period10/04/0713/04/07

Fingerprint

Dive into the research topics of 'Aggregating and deploying network access control policies'. Together they form a unique fingerprint.

Cite this