MetaCartSign in to MyCiteSeer

Include Citations | Advanced Search | Help

Include Citations | Advanced Search | Help

  The STRONGMAN Architecture (2003) [12 citations — 3 self]

Download:
Download as a PDF | Download as a PS
by Angelos D. Keromytis, Sotiris Ioannidis, Michael B. Greenwald, Jonathan M. Smith
In Proceedings, DARPA Information Survivability Confernce and Exhibition
ftp://ftp.cis.upenn.edu/pub/mbgreen/papers/discex03.ps.gz
Add To MetaCart

Abstract:

The design principle of restricting local autonomy only where necessary for global robustness has led to a scalable Internet. Unfortunately, this scalability and capacity for distributed control has not been achieved in the mechanisms for specifying and enforcing security policies. This shortcoming must be overcome if end-to-end security mechanisms (such as IPsec or TLS) are to ever replace solutions of short-term convenience such as firewalls. The STRONGMAN (for Scalable TRust Of Next Generation MANagement) system offers three new approaches to scalability, applying the principle of local policy enforcement complying with global security policies. First is the use of a compliance checker to provide great local autonomy within the constraints of a global security policy. Second is a mechanism to compose policy rules into a coherent enforceable set, e.g., at the boundaries of two locally autonomous application domains. Third is the "lazy instantiation " of policies to reduce the amount of state that enforcement points need to maintain. We demonstrate the use of these approaches in the design, implementation, and measurements of a distributed firewall. Our experiments show that, under certain circumstances, performance can improve over the traditionalfirewall approach.

Citations

646 End-to-end arguments in system design – Saltzer, Reed, et al. - 1984
309 The design philosophy of the DARPA Internet protocols – CLARK - 1988
167 Firewalls and Internet Security: Repelling the Wily Hacker – Cheswick, Bellovin - 1994
109 Implementing a distributed firewall – Ioannidis, Keromytis, et al. - 2000
74 Firmato: A novel firewall management toolkit – Bartal, Mayer, et al. - 1999
62 Simple and flexible datagram access controls for Unix-based gateways – Mogul - 1989
58 Access control in an open distributed environment – Hayton, Bacon, et al. - 1998
49 Filtering Postures: Local Enforcement for Global Policies – Guttman - 1997
44 The KeyNote Trust – Blaze, Feigenbaum, et al. - 1999
30 Distributed Firewalls. ;login: magazine, special issue on security – Bellovin - 1999
15 Policy-Based Management: Bridging the Gap – Hinrichs - 1999
14 Designing an Academic Firewall. Policy, Practice and Experience with SURF – Greenwald, Singhal, et al. - 1996
14 Design and Performance of the OpenBSD Stateful Packet Filter (pf – Hartmeier - 2002
12 Controlling network communication with domain and type enforcement – Sherman, Sterne, et al. - 1995
8 Security Policy Coordination for Heterogeneous Information Systems – Hale, Galiasso, et al. - 1999
8 An architecture for advanced packet filtering – Molitor - 1995
8 The Multilayer Firewall – Nessett, Humenn - 1998
7 A Modular Approach to Composing Access Policies – Bonatti, Vimercati, et al. - 2000
6 An Analysis Of Security On The Internet – Howard - 1989
6 Managing Security in Dynamic Networks – Konstantinou, Bhatt, et al. - 1999
5 A Network of Firewalls: An Implementation Example – McKenney, Woycke, et al. - 1995