• DocumentCode
    2124339
  • Title

    Self-Configuration of Network Security

  • Author

    Chen, Huoping ; Al-Nashif, Youssif B. ; Qu, Guangzhi ; Hariri, Salim

  • Author_Institution
    Univ. of Arizona, Tucson
  • fYear
    2007
  • fDate
    15-19 Oct. 2007
  • Firstpage
    97
  • Lastpage
    97
  • Abstract
    The proliferation of networked systems and services along with their exponential growth in complexity and size has increased the control and management complexity of such systems and services by several orders of magnitude. As a result, management tools have failed to cope with and handle the complexity, dynamism, and coordination among network attacks. In this paper, we present a self-configuration approach to control and manage the security mechanisms of large scale networks. Self-configuration enables the system to automatically configure security system and change the configuration of its resources and their operational policies at runtime in order to manage the system security. Our self-configuration approach is implemented using two software modules: component management interface (CMI) to specify the configuration and operational policies associated with each component that can be a hardware resource or a software component; and component runtime manager (CRM) that manages the component operations using the policies defined in CMI. We have used the self-configuration framework to experiment with and evaluate different mechanisms and strategies to detect and protect against a wide range of network attacks.
  • Keywords
    configuration management; object-oriented programming; security of data; component management interface; component runtime manager; configuration policy; large scale networks; network attack; network security; self-configuration; software component; software module; system security; Computer network management; Computer networks; Control systems; Intrusion detection; Large-scale systems; Protection; Resource management; Runtime; Security; Taxonomy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enterprise Distributed Object Computing Conference, 2007. EDOC 2007. 11th IEEE International
  • Conference_Location
    Annapolis, MD
  • ISSN
    1541-7719
  • Print_ISBN
    978-0-7695-2891-5
  • Type

    conf

  • DOI
    10.1109/EDOC.2007.45
  • Filename
    4383985