• DocumentCode
    3334377
  • Title

    Domain and type enforcement firewalls

  • Author

    Oostendorp, K.A. ; Badger, Lee ; Vance, Christopher D. ; Morrison, Wayne G. ; Petkac, Michael J. ; Sherman, David L. ; Sterne, Daniel F.

  • Author_Institution
    Trusted Inf. Syst. Inc., Glenwood, MD, USA
  • fYear
    1997
  • fDate
    8-12 Dec 1997
  • Firstpage
    122
  • Lastpage
    132
  • Abstract
    Internet connected organizations often employ an Internet firewall to mitigate risks of system penetration, data theft, data destruction, and other security breaches. Conventional Internet firewalls, however, impose an overly simple inside vs outside model of security that is incompatible with many business practices that require extending limited trust to external entities. The paper reports on our experience with an enhanced security firewall based on Domain and Type Enforcement (DTE), a strong but flexible form of access control. A DTE firewall provides several benefits. First, it runs application level proxies in restrictive domains, thereby increasing security, and runs network services such as HTTP and FTP under DTE controls, thereby reducing risks that network based attacks will compromise local resources. Second, a DTE firewall coordinates role based security policies that span networks by passing DTE security attributes between DTE clients and servers. These attributes allow security policies at the endpoints to be coordinated; such coordination adds defense in depth to the traditional firewall security perimeter: this permits safe exportation of normally risky services such as NFS. Finally, a DTE firewall interoperates with “non DTE” systems and associates DTE security attributes with these systems so their interaction with DTE clients or servers can be controlled. We describe the design of a prototype DTE firewall system and informally evaluate its security, compatibility, functionality, and performance
  • Keywords
    Internet; authorisation; client-server systems; computer network management; DTE clients; DTE firewall; DTE security attributes; Domain and Type Enforcement; FTP; HTTP; Internet connected organizations; Internet firewall; access control; application level proxies; business practices; external entities; local resources; network based attacks; network services; restrictive domains; role based security policies; security breaches; security policies; servers; system penetration; type enforcement firewalls; Access control; Control systems; Data security; Internet; Mobile agents; Network servers; Protection; Protocols; Tunneling; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 1997. Proceedings., 13th Annual
  • Conference_Location
    San Diego, CA
  • ISSN
    1063-9527
  • Print_ISBN
    0-8186-8274-4
  • Type

    conf

  • DOI
    10.1109/CSAC.1997.646182
  • Filename
    646182