Access Control Policy Enforcement for Zero-Trust-Networking

被引:0
|
作者
Vanickis, Romans [1 ]
Jacob, Paul [1 ]
Dehghanzadeh, Sohelia [1 ]
Lee, Brian [1 ]
机构
[1] Athlone Inst Technol, Software Res Inst, Athlone, Ireland
关键词
zero trust networking; risk-based access control; trust; policy enforcement; firewall; network zone; micro-segment;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The evolution of the enterprise computing landscape towards emerging trends such as fog/edge computing and the Industrial Internet of Things (IIoT) are leading to a change of approach to securing computer networks to deal with challenges such as mobility, virtualized infrastructures, dynamic and heterogeneous user contexts and transaction-based interactions. The uncertainty introduced by such dynamicity introduces greater uncertainty into the access control process and motivates the need for risk-based access control decision making. Thus, the traditional perimeter-based security paradigm is increasingly being abandoned in favour of a so called "zero trust networking" (ZTN). In ZTN networks are partitioned into zones with different levels of trust required to access the zone resources depending on the assets protected by the zone. All accesses to sensitive information is subject to rigorous access control based on user and device profile and context. In this paper we outline a policy enforcement framework to address many of open challenges for risk-based access control for ZTN. We specify the design of required policy languages including a generic firewall policy language to express firewall rules. We design a mechanism to map these rules to specific firewall syntax and to install the rules on the firewall. We show the viability of our design with a small proof-ofconcept.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Decentralized Policy Enforcement in Zero Trust Architectures
    Creutz, Lars
    Dartmann, Guido
    [J]. 2023 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2024,
  • [2] Access Control Enforcement in IoT: state of the art and open challenges in the Zero Trust era
    Colombo, Pietro
    Ferrari, Elena
    Tumer, Engin Deniz
    [J]. 2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021), 2021, : 156 - 163
  • [3] Secure Content Distribution with Access Control Enforcement in Named Data Networking
    Htet Hlaing, Htet
    Funamoto, Yuki
    Mambo, Masahiro
    [J]. SENSORS, 2021, 21 (13)
  • [4] Access Control Enforcement Delegation for Information-Centric Networking Architectures
    Fotiou, Nikos
    Marias, Giannis F.
    Polyzos, George C.
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (04) : 497 - 502
  • [5] Checking Policy Enforcement in an Access Control Aspect Model
    Song, Eunjee
    France, Robert
    Ray, Indrakshi
    Kim, Hanil
    [J]. INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2008, 11 (05): : 541 - 552
  • [6] Access Control for Database Applications: Beyond Policy Enforcement
    Zhang, Wen
    Panda, Aurojit
    Shenker, Scott
    [J]. PROCEEDINGS OF THE 19TH WORKSHOP ON HOT TOPICS IN OPERATING SYSTEMS, HOTOS 2023, 2023, : 223 - 230
  • [7] Separating access control policy, enforcement, and functionality in extensible systems
    Grimm, R
    Bershad, BN
    [J]. ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2001, 19 (01): : 36 - 70
  • [8] Label-based access control policy enforcement and management
    Zhou, Wei
    Raja, Vinesh H.
    Meinel, Christoph
    Ahmad, Munir
    [J]. SNPD 2006: SEVENTH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING ARTIFICIAL INTELLIGENCE, NETWORKING, AND PARALLEL/DISTRIBUTED COMPUTING, PROCEEDINGS, 2006, : 395 - +
  • [9] Enforcement of Access Control Policy for Mobile Ad Hoc Networks
    Maity, Soumya
    Ghosh, Soumya K.
    [J]. PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2012, : 47 - 52
  • [10] The Policy Machine: A novel architecture and framework for access control policy specification and enforcement
    Ferraiolo, David
    Atluri, Vijayalakshmi
    Gavrila, Serban
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2011, 57 (04) : 412 - 424