DocumentCode :
1925017
Title :
Managing network security policies in tactical MANETs using DRAMA
Author :
Cheng, Yuu-Heng ; Ghosh, Abhrajit ; Chadha, Ritu ; Gary, M.L. ; Wolberg, Michelle ; Chiang, C. Jason ; Hadynski, Gregory
Author_Institution :
Knowledge-Based Syst., Telcordia, Piscataway, NJ, USA
fYear :
2010
fDate :
Oct. 31 2010-Nov. 3 2010
Firstpage :
960
Lastpage :
964
Abstract :
Military networks are required to adapt their access control policies to the Information Operations Condition (INFOCON) levels to minimize the impact of potential malicious activities. Such adaptations must be automated to the extent possible, consistent with mission requirements, and applied network-wide. In this paper, we present a Policy-Based Network Security (PBNS) management approach for tactical MANETs. This approach leverages the DRAMA policy based network management system and the Smart Firewall system to meet the above requirement. It allows administrators to specify low-level network access control policies for each INFOCON level using high-level policies (adapted from the Smart Firewalls approach). The high-level policies are securely distributed to all the policy decision points in the network, which evaluate and enforce policies in a distributed manner. As a consequence of enforcing policies in response to INFOCON level changes, appropriate access control policies will be derived and applied to local firewall devices without human intervention. Thus, operator burden can be significantly reduced and inadvertent errors can be avoided.
Keywords :
authorisation; military communication; mobile ad hoc networks; telecommunication network management; telecommunication security; DRAMA policy; INFOCON; PBNS management; Smart Firewall system; dynamic re-addressing and management for the army; information operation condition; low-level network access control policy; military networks; mobile ad hoc networks; policy-based network security management; tactical MANET; Access control; Ad hoc networks; Fires; Intrusion detection; Mobile computing; Web services; MANET; firewalls; network access control; network operations; policy-based management; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
MILITARY COMMUNICATIONS CONFERENCE, 2010 - MILCOM 2010
Conference_Location :
San Jose, CA
ISSN :
2155-7578
Print_ISBN :
978-1-4244-8178-1
Type :
conf
DOI :
10.1109/MILCOM.2010.5679579
Filename :
5679579
Link To Document :
بازگشت