Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2006

Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach

Résumé

This paper presents a new framework based on a meta-policy linked to a new intrusion detection approach. It deploys a MAC kernel within a distributed system while guaranteeing the consistency of the security policy, preventing any accidental or malicious update of the local policies of each host. Access control decisions are resolved locally in accordance with a meta-policy. At the same time, the framework allows the evolution of the distributed policy without any network communication, and also guarantees that it satisfies the global security properties defined in the meta-policy. The combined policy and IDS approach relies on Trusted Operating Systems integrating MAC and RBAC. The proposed architecture controls a wider set of attacks and provides increased fault-tolerance, compared to other existing distributed access control approaches and policy-based IDS techniques. Details are given about languages used for the meta-policy, and implementation of the framework.
Fichier non déposé

Dates et versions

hal-00082278 , version 1 (27-06-2006)

Identifiants

Citer

Mathieu Blanc, Jérémy Briffaut, Jean-François Lalande, Christian Toinard. Distributed control enabling consistent MAC policies and IDS based on a meta-policy approach. POLICY 2006, Jun 2006, University of Western Ontario, London, Canada. pp.153-156, ⟨10.1109/POLICY.2006.15⟩. ⟨hal-00082278⟩
66 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More