Programmable In-Network Security for Context-aware BYOD Policies

被引:0
|
作者
Kang, Qiao [1 ]
Xue, Lei [2 ]
Morrison, Adam [1 ]
Tang, Yuxin [1 ]
Chen, Ang [1 ]
Luo, Xiapu [2 ]
机构
[1] Rice Univ, Houston, TX 77251 USA
[2] Hong Kong Polytech Univ, Hong Kong, Peoples R China
关键词
AUTHENTICATION; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bring Your Own Device (BYOD) has become the new norm for enterprise networks, but BYOD security remains a top concern. Context-aware security, which enforces access control based on dynamic runtime context, is a promising approach. Recent work has developed SDN solutions to collect device contexts and enforce access control at a central controller. However, the central controller could become a bottleneck and attack target. Processing context signals at the remote controller is also too slow for real-time decision change. We present a new paradigm, programmable in-network security (Poise), which is enabled by the emergence of programmable switches. At the heart of Poise is a novel security primitive, which can be programmed to support a wide range of context-aware policies in hardware. Users of Poise specify concise policies, and Poise compiles them into different configurations of the primitive in P4. Compared with traditional SDN defenses, Poise is resilient to control plane saturation attacks, and it dramatically increases defense agility.
引用
收藏
页码:595 / 612
页数:18
相关论文
共 50 条
  • [31] Securing Access to Healthcare Data with Context-aware Policies
    Psarra, Evgenia
    Patiniotakis, Ioannis
    Verginadis, Yiannis
    Apostolou, Dimitris
    Mentzas, Gregoris
    [J]. 2020 11TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS AND APPLICATIONS (IISA 2020), 2020, : 51 - 56
  • [32] Context-aware security for the Intra-Electric Vehicle Network under energy constraints
    Fraiji, Yosra
    Ben Azzouz, Lamia
    Trojet, Wassim
    Hoblos, Ghaleb
    Saidane, Leila Azouz
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 97
  • [33] Dynamic Context-Aware Security in a Tactical Network using Attribute-Based Encryption
    Inshi, Saad
    Chowdhury, Rasel
    Ould-Slimane, Hakima
    Talhi, Chamseddine
    [J]. 2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2022,
  • [34] Context-Aware Autonomous Security Assertion for Industrial IoT
    Tariq, Usman
    Aseeri, Ahmad O.
    Alkatheiri, Mohammed Saeed
    Zhuang, Yu
    [J]. IEEE ACCESS, 2020, 8 : 191785 - 191794
  • [35] Sensors for Context-Aware Smart Healthcare: A Security Perspective
    Batista, Edgar
    Angels Moncusi, M.
    Lopez-Aguilar, Pablo
    Martinez-Balleste, Antoni
    Solanas, Agusti
    [J]. SENSORS, 2021, 21 (20)
  • [36] Context-aware security: Linguistic mechanisms and static analysis
    Bodei, Chiara
    Degano, Pierpaolo
    Galletta, Letterio
    Salvatori, Francesco
    [J]. JOURNAL OF COMPUTER SECURITY, 2016, 24 (04) : 427 - 477
  • [37] Application of Security Ontology to Context-Aware Alert Analysis
    Xu, Hui
    Xiao, Debao
    Wu, Zheng
    [J]. PROCEEDINGS OF THE 8TH IEEE/ACIS INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCE, 2009, : 171 - 176
  • [38] Context-Aware Security Solutions for Cyber Physical Systems
    Wan, Kaiyu
    Alagar, Vangalur
    [J]. Context-Aware Systems and Applications, (ICCASA 2012), 2013, 109 : 18 - 29
  • [39] Context-Aware Security Using Internet of Things Devices
    Trnka, Michal
    Tomasek, Martin
    Cerny, Tomas
    [J]. INFORMATION SCIENCE AND APPLICATIONS 2017, ICISA 2017, 2017, 424 : 706 - 713
  • [40] Cerberus: A context-aware security scheme for smart spaces
    Al-Muhtadi, J
    Ranganathan, A
    Campbell, R
    Mickunas, MD
    [J]. PROCEEDINGS OF THE FIRST IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS (PERCOM 2003), 2003, : 489 - 496