Enforcing Multilevel Security Policies in Database-Defined Networks using Row-Level Security

A. Al-Haj, B. Aziz
{"title":"Enforcing Multilevel Security Policies in Database-Defined Networks using Row-Level Security","authors":"A. Al-Haj, B. Aziz","doi":"10.1109/NetSys.2019.8854491","DOIUrl":null,"url":null,"abstract":"Despite the wide of range of research and technologies that deal with the problem of routing in computer networks, there remains a gap between the level of network hardware administration and the level of business requirements and constraints. Not much has been accomplished in literature in order to have a direct enforcement of such requirements on the network. This paper presents a new solution in specifying and directly enforcing security policies to control the routing configuration in a software-defined network by using Row-Level Security checks which enable fine-grained security policies on individual rows in database tables. We show, as a first step, how a specific class of such policies, namely multilevel security policies, can be enforced on a database-defined network, which presents an abstraction of a network's configuration as a set of database tables. We show that such policies can be used to control the flow of data in the network either in an upward or downward manner.","PeriodicalId":291245,"journal":{"name":"2019 International Conference on Networked Systems (NetSys)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-01-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Networked Systems (NetSys)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NetSys.2019.8854491","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Despite the wide of range of research and technologies that deal with the problem of routing in computer networks, there remains a gap between the level of network hardware administration and the level of business requirements and constraints. Not much has been accomplished in literature in order to have a direct enforcement of such requirements on the network. This paper presents a new solution in specifying and directly enforcing security policies to control the routing configuration in a software-defined network by using Row-Level Security checks which enable fine-grained security policies on individual rows in database tables. We show, as a first step, how a specific class of such policies, namely multilevel security policies, can be enforced on a database-defined network, which presents an abstraction of a network's configuration as a set of database tables. We show that such policies can be used to control the flow of data in the network either in an upward or downward manner.
使用行级安全在数据库定义的网络中执行多级安全策略
尽管处理计算机网络路由问题的研究和技术范围广泛,但网络硬件管理水平与业务需求和约束水平之间仍然存在差距。为了在网络上直接执行这些要求,文献中没有完成多少工作。本文提出了一种新的解决方案,通过使用行级安全检查来指定和直接执行安全策略来控制软件定义网络中的路由配置,这种检查在数据库表的单个行上启用了细粒度的安全策略。作为第一步,我们将展示如何在数据库定义的网络上实施此类策略的特定类,即多层安全策略,它将网络配置的抽象表示为一组数据库表。我们展示了这样的策略可以用于以向上或向下的方式控制网络中的数据流。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信