• DocumentCode
    1655154
  • Title

    Domain and type enforcement firewalls

  • Author

    Oostendorp, Karen A. ; Badger, Lee ; Vance, Christopher D. ; Morrison, Wayne G. ; Petkac, Michael J. ; Sherman, David L. ; Sterne, Daniel F.

  • Author_Institution
    Trusted Inf. Syst. Inc., Glenwood, MD, USA
  • Volume
    1
  • fYear
    2000
  • fDate
    6/22/1905 12:00:00 AM
  • Firstpage
    351
  • Abstract
    Internet-connected organizations often employ an Internet firewall to mitigate risks of system penetration, data theft, data destruction, and other security breaches. Conventional Internet firewalls, however, impose an overly simple inside-vs-outside model of security that is incompatible with many business practices that require extending limited trust to external entities, for example, suppliers, bankers, accountants, advisors, consultants, partners, customers, and allies. Additionally, firewall security perimeters are somewhat weak: they provide no protection from inside attacks and do not protect sensitive data, which can be exported by tunneling through permitted protocols. As the Internet evolves towards applets, mobile agents, and object frameworks, these problems likely will worsen. This paper reports on our experience with an enhanced security firewall based on domain and type enforcement (DTE), a strong but flexible form of access control. A DTE firewall provides several benefits. We describe the design of a prototype DTE firewall system and informally evaluate its security, compatibility, functionality and performance
  • Keywords
    Internet; authorisation; business data processing; software performance evaluation; telecommunication security; Internet; Internet firewall; access control; applets; data destruction; data theft; domain enforcement firewalls; mobile agents; object frameworks; organizations; performance evaluation; security breach; system penetration; type enforcement firewalls; Access control; Computer security; Data security; Internet; Mobile agents; Network servers; Protection; Prototypes; Tunneling; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference and Exposition, 2000. DISCEX '00. Proceedings
  • Conference_Location
    Hilton Head, SC
  • Print_ISBN
    0-7695-0490-6
  • Type

    conf

  • DOI
    10.1109/DISCEX.2000.825039
  • Filename
    825039