Skip to main navigation Skip to search Skip to main content

Protection of components based on a smart-card enhanced security module

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We present in this paper the use of a security mechanism to handle the protection of network security components, such as Firewalls and Intrusion Detection Systems. Our approach consists of a kernel-based access control method which intercepts and cancels forbidden system calls launched by a potential remote attacker. This way, even if the attacker gains administration permissions, she will not achieve her purpose. To solve the administration constraints of our approach, we use a smart-card based authentication mechanism for ensuring the administrator's identity. Through the use of a cryptographic protocol, the protection mechanism verifies administrator's actions before holding her the indispensable privileges to manipulate a component. Otherwise, the access control enforcement will come to its normal operation. We also show in this paper an overview of the implementation of this mechanism on a research prototype, developed for GNU/Linux systems, over the Linux Security Modules (LSM) framework.

Original languageEnglish
Title of host publicationCritical Information Infrastructures Security - First International Workshop, CRITIS 2006, Revised Papers
Pages128-139
Number of pages12
DOIs
Publication statusPublished - 1 Dec 2006
Externally publishedYes
Event1st International Workshop on Critical Information Infrastructures Security, CRITIS 2006 - Samos, Greece
Duration: 31 Aug 20061 Sept 2006

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4347 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference1st International Workshop on Critical Information Infrastructures Security, CRITIS 2006
Country/TerritoryGreece
CitySamos
Period31/08/061/09/06

Fingerprint

Dive into the research topics of 'Protection of components based on a smart-card enhanced security module'. Together they form a unique fingerprint.

Cite this