• DocumentCode
    393368
  • Title

    The STRONGMAN architecture

  • Author

    Keromytis, Angelos D. ; Ioannidis, Sotiris ; Greenwald, Michael B. ; Smith, Jonathan M.

  • Author_Institution
    Dept. of Comput. Sci., Columbia Univ., New York, NY, USA
  • Volume
    1
  • fYear
    2003
  • fDate
    22-24 April 2003
  • Firstpage
    178
  • Abstract
    The design principle of restricting local autonomy only where necessary for global robustness has led to a scalable Internet. Unfortunately, this scalability and capacity for distributed control has not been achieved in the mechanisms for specifying and enforcing security policies. This shortcoming must be overcome if end-to-end security mechanisms (such as IPsec or TLS) are to ever replace solutions of short-term convenience such as firewalls. The STRONGMAN (for Scalable Trust Of Next Generation Management) system offers three new approaches to scalability, applying the principle of local policy enforcement complying with global security policies. First is the use of a compliance checker to provide great local autonomy within the constraints of a global security policy. Second is a mechanism to compose policy rules into a coherent enforceable set, e.g. at the boundaries of two locally autonomous application domains. Third is the "lazy instantiation" of policies to reduce the amount of state that enforcement points need to maintain. We demonstrate the use of these approaches in the design, implementation, and measurements of a distributed firewall. Our experiments show that, under certain circumstances, performance can improve over the traditional-firewall approach.
  • Keywords
    Internet; authorisation; telecommunication security; STRONGMAN architecture; Scalable Trust Of Next Generation Management system; compliance checker; distributed control; distributed firewall; end-to-end security mechanisms; global security policies; lazy instantiation; local autonomy; local policy enforcement; scalable Internet; Distributed control; Internet; Robustness; Scalability; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference and Exposition, 2003. Proceedings
  • Print_ISBN
    0-7695-1897-4
  • Type

    conf

  • DOI
    10.1109/DISCEX.2003.1194883
  • Filename
    1194883