• DocumentCode
    2574449
  • Title

    Leveraging IPsec for Mandatory Per-Packet Access Control

  • Author

    Jaeger, Trent ; King, David H. ; Butler, Kevin R. ; Hallyn, Serge ; Latten, Joy ; Zhang, Xiaolan

  • Author_Institution
    Syst. & Internet Infrastruct. Lab., Pennsylvania State Univ., University Park, PA
  • fYear
    2006
  • fDate
    Aug. 28 2006-Sept. 1 2006
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Mandatory access control (MAC) enforcement is becoming available for commercial environments. For example, Linux 2.6 includes the Linux security modules (LSM) framework that enables the enforcement of MAC policies (e.g., type enforcement or multi-level security) for individual systems. While this is a start, we envision that MAC enforcement should span multiple machines. The goal is to be able to control interaction between applications on different machines based on MAC policy. In this paper, we describe a recent extension of the LSM framework that enables labeled network communication via IPsec that is now available in mainline Linux as of version 2.6.16. This functionality enables machines to control communication with processes on other machines based on the security label assigned to an IPsec security association. We outline a security architecture based on labeled IPsec to enable distributed MAC authorization. In particular, we examine the construction of a xinetd service that uses labeled IPsec to limit client access on Linux 2.6.16 systems. We also discuss the application of labeled IPsec to distributed storage and virtual machine access control
  • Keywords
    IP networks; Linux; access protocols; authorisation; telecommunication control; virtual machines; IPsec security association; Linux 2.6.16; Linux security modules framework; distributed MAC authorization; distributed storage; labeled network communication; mandatory per-packet access control; multi-level security; type enforcement; virtual machine access control; xinetd service; Access control; Authorization; Communication system control; Communication system security; Control systems; Grid computing; Kernel; Linux; Permission; Sockets;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Securecomm and Workshops, 2006
  • Conference_Location
    Baltimore, MD
  • Print_ISBN
    1-4244-0423-1
  • Electronic_ISBN
    1-4244-0423-1
  • Type

    conf

  • DOI
    10.1109/SECCOMW.2006.359530
  • Filename
    4198790