Transparent network security policy enforcement

被引:0
|
作者
Keromytis, AD [1 ]
Wright, JL [1 ]
机构
[1] Univ Penn, Distributed Syst Lab, Philadelphia, PA 19104 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent work in the area of network security, such as IPsec, provides mechanisms for securing the traffic between any two interconnected hosts. However, it is not always possible, economical, or even practical from an administration and operational point of view to upgrade the software and configuration of all the nodes in a network to support such security protocols. One apparent solution to this problem is the use of security gateways that apply the relevant security protocols on behalf of the protected nodes, under the assumption that the "last hop" between the security gateway and the end node is safe without cryptography. Such a gateway can be set to enforce specific security policies for different types of traffic. While this solution is appealing in static scenarios (such as building so-called "intranets"), the use of Layer-3 (network) routers as security gateways presents some transparency and configuration problems with regards to peer authentication in the automated key management protocol. This paper describes the architecture and implementation of a Layer-2 (link layer) bridge with extensions for offering Layer-3 security services. We extend the OpenBSD ethernet bridge to perform simple IP packet filtering and IPsec processing for incoming and outgoing packets on behalf of a protected node, completely transparently to both the protected and the remote communication endpoint. The same mechanism may be used to construct "virtual local area networks," by establishing IPsec tunnels between OpenBSD bridges connected geographically separated LANs. As our system operates in the link layer, there is no need for software or configuration changes in the protected nodes.
引用
收藏
页码:215 / 225
页数:11
相关论文
共 50 条
  • [1] Efficient Network Security Policy Enforcement With Policy Space Analysis
    Wang, Xiang
    Shi, Weiqi
    Xiang, Yang
    Li, Jun
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2016, 24 (05) : 2958 - 2970
  • [2] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    [J]. 2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100
  • [3] A novel approach for integrating security policy enforcement with dynamic network virtualization
    Basile, Cataldo
    Lioy, Antonio
    Pitscheider, Christian
    Valenza, Fulvio
    Vallini, Marco
    [J]. 2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [4] SERENIoT: Distributed Network Security Policy Management and Enforcement for Smart Homes
    Thomasset, Corentin
    Barrera, David
    [J]. 36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020), 2020, : 542 - 555
  • [5] A flexible architecture for security policy enforcement
    McDaniel, P
    Prakash, A
    [J]. DARPA INFORMATION SURVIVABILITY CONFERENCE AND EXPOSITION, VOL II, PROCEEDINGS, 2003, : 234 - 239
  • [6] Patterns in security enforcement policy development
    Thomsen, Dan
    [J]. DEXA 2007: 18TH INTERNATIONAL CONFERENCE ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2007, : 744 - 748
  • [7] Walls of security and policy enforcement in Belfast
    Ballif, Florine
    [J]. MEMOIRES IDENTITES MARGINALITES DANS LE MONDE OCCIDENTAL CONTEMPORAIN, 2009, 5
  • [8] Dynamic Security Policy Enforcement on Android
    Vanco, Matus
    Aron, Lukas
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (09): : 141 - 148
  • [9] An Android Security Policy Enforcement Tool
    Cotterell, Kathryn
    Welch, Ian
    Chen, Aaron
    [J]. INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS, 2015, 61 (04) : 311 - 320
  • [10] Policy Enforcement for Big Data security
    Al-Shomrani, Abdullah
    Fathy, Fathy
    Jambi, Kamal
    [J]. 2017 2ND INTERNATIONAL CONFERENCE ON ANTI-CYBER CRIMES (ICACC), 2017, : 70 - 74