• DocumentCode
    3218452
  • Title

    Automatic management of network security policy

  • Author

    Burns, J. ; Cheng, A. ; Gurung, P. ; Rajagopalan, S. ; Rao, P. ; Rosenbluth, D. ; Surendran, A.V. ; Martin, D.M., Jr.

  • Volume
    2
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    12
  • Abstract
    The paper describes work in our project funded by the DARPA Dynamic Coalitions program to design, develop, and demonstrate a system for automatically managing security policies in dynamic networks. Specifically, we aim to reduce human involvement in network management by building a practical network reconfiguration system so that simple security policies stated as positive and negative invariants are upheld as the network changes. The focus of this project is a practical tool to help systems administrators verifiably enforce simple multi-layer network security policies. Our key design considerations are computational cost of policy validation and the power of the enforcement primitives. The central component is a policy engine populated by models of network elements and services that validates policies and computes new configuration settings for network elements when they are violated. We instantiate our policy enforcement tool using a monitoring and instrumentation layer that reports network changes as they occur and implements configuration changes computed by the policy engine
  • Keywords
    computer network management; management of change; military computing; security of data; DARPA Dynamic Coalitions program; automatic network security policy management; computational cost; configuration changes; dynamic networks; enforcement primitives; instrumentation layer; monitoring layer; multi-layer network security policies; negative invariants; network changes; network reconfiguration system; policy validation; positive invariants; Buildings; Computational efficiency; Computer network management; Computer networks; Engines; Humans; Monitoring; Power system modeling; Power system security; Project management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
  • Conference_Location
    Anaheim, CA
  • Print_ISBN
    0-7695-1212-7
  • Type

    conf

  • DOI
    10.1109/DISCEX.2001.932156
  • Filename
    932156