MetaCartSign in to MyCiteSeer

Include Citations | Advanced Search | Help

Include Citations | Advanced Search | Help

  A Protection Scheme For Security Policies In Ubiquitous Environments Using One-Way Functions

Download:
Download as a PDF
by Håkan Kvarnström, Hans Hedbom
http://www.teco.edu/~philip/ubicomp2002ws/organize/chalmers.pdf
Add To MetaCart

Abstract:

This paper addresses the problem of protecting security policies and other security-related information in security mechanisms and products, such as the detection policy in an Intrusion Detection System (IDS) or the filtering policy in a firewall. Unauthorized disclosure of the such information is particularly serious, since it might reveal the fundamental principles and methods for the security and protection of the whole system or network, which is much more far-reaching that the protection of the target system or security mechanism itself. This problem is especially noticeable in ubiquitous environments where a possible large number of nodes need knowledge about the security policy of their domain. In order to avoid this risk we suggest that security information should be protected using one-way functions and the paper suggests a basic scheme for protecting stateless policies. A stateless policy is a policy that only takes the current event into consideration when decisions are made and not the preceding chain of events. Thus, the process of comparing events towards the policy, i.e. making decisions, could be done in much the same way that passwords are hashed and compared in UNIX systems. However, one important distinction is that security policies contain a certain variability that must be handled and a method for this is discussed. The suggested scheme is very basic and has certain drawbacks as regards practical implementation, but does still clearly demonstrate the protection principle. We expect further research to result in extended methods that are more suitable for practical design.

Citations

141 Password security: A case history – Morris, Thompson - 1979
70 Network Intrusion Detection: An Analyst’s Handbook – Northcutt - 1999
40 Building Internet Firewalls – Chapman, Zwicky - 1995
33 UNIX Password Security - Ten Years Later – Feldmeier, Karn - 1990
18 Playing “hide and seek” with stored keys – Shamir, Someren - 1999
14 Architectures and Formal Representations for Secure Systems – Neumann - 1996
6 Collisionful keyed hash functions with selectable collisions – Gong - 1995
5 On selectable collisionful hash functions – Bakhtiari, Safavi-Naini, et al. - 1996
3 Firewalls and Internet Security: Repelling the Wily – Cheswick, Bellovin - 1994
3 The Common Intrusion Detection Framework – Chen, Tung, et al. - 1998
2 On the Weakness of Gong´s Collisionful Hash Function – Bakhtiari, Pieprzyk - 1997
2 Security implications of distributed intrusion detection architectures – Hedbom, KvarnstrSm, et al. - 1999
2 Risks and dangers of security extensions – Hedbom, Lindskog, et al.
1 A Fuzzy Commitmen Scheme – Juels, Wattenberg