{"title":"Policy based access control framework for large networks","authors":"Haixin Duan, Jianping Wu, Li Xing","doi":"10.1109/ICON.2000.875800","DOIUrl":null,"url":null,"abstract":"This paper focus on the issues of management and throughput of firewalls (or screening routers) applied in transit networks. On the one hand, manual configuration of a large amount of firewalls distributed in many access points can not meet the global security requirements in the open and dynamic environment. On the other hand, the ordinal lookup of filtering rules in each individual firewall results in great decrease of throughput. Aimed at a typical transit network and its security policy requirements, a policy-based access control framework (PACF) is proposed. This framework is based on three levels of abstract access control policy: organizational access control policy (OACP), global access control policy (GACP) and local access control policy (LACP). The GACP, which comes from the results of IDSes and search engines according to OACP, is automatically and dynamically distributed to firewalls as LACPs. Each LACP is then enforced by an individual firewall. Some key algorithms for distribution of GACP and enforcement of LACP are described. A hash-based algorithm is proposed, for lookup of filtering rules in LACP. Under an environment with policy requirements described in this paper the new algorithm reduces the time complexity of lookup from O(N) of the traditional sequential algorithm to O(1), which therefore increases largely the throughput of firewalls.","PeriodicalId":191244,"journal":{"name":"Proceedings IEEE International Conference on Networks 2000 (ICON 2000). Networking Trends and Challenges in the New Millennium","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2000-09-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings IEEE International Conference on Networks 2000 (ICON 2000). Networking Trends and Challenges in the New Millennium","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICON.2000.875800","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
This paper focus on the issues of management and throughput of firewalls (or screening routers) applied in transit networks. On the one hand, manual configuration of a large amount of firewalls distributed in many access points can not meet the global security requirements in the open and dynamic environment. On the other hand, the ordinal lookup of filtering rules in each individual firewall results in great decrease of throughput. Aimed at a typical transit network and its security policy requirements, a policy-based access control framework (PACF) is proposed. This framework is based on three levels of abstract access control policy: organizational access control policy (OACP), global access control policy (GACP) and local access control policy (LACP). The GACP, which comes from the results of IDSes and search engines according to OACP, is automatically and dynamically distributed to firewalls as LACPs. Each LACP is then enforced by an individual firewall. Some key algorithms for distribution of GACP and enforcement of LACP are described. A hash-based algorithm is proposed, for lookup of filtering rules in LACP. Under an environment with policy requirements described in this paper the new algorithm reduces the time complexity of lookup from O(N) of the traditional sequential algorithm to O(1), which therefore increases largely the throughput of firewalls.
本文主要研究了在传输网络中应用的防火墙(或筛选路由器)的管理和吞吐量问题。一方面,人工配置分布在多个接入点的大量防火墙已不能满足开放、动态环境下的全局安全需求。另一方面,在每个单独的防火墙中依次查找过滤规则会导致吞吐量大大降低。针对典型的公交网络及其安全策略需求,提出了一种基于策略的访问控制框架(PACF)。该框架基于三个层次的抽象访问控制策略:组织访问控制策略(organization access control policy, OACP)、全局访问控制策略(global access control policy, GACP)和本地访问控制策略(local access control policy, LACP)。GACP是由ids和搜索引擎根据OACP得到的结果,作为lacp自动动态地分发到防火墙中。然后,每个LACP由单独的防火墙执行。介绍了GACP分发和LACP实施的一些关键算法。提出了一种基于哈希的LACP过滤规则查找算法。在本文所描述的具有策略要求的环境下,新算法将传统顺序算法的查找时间复杂度从O(N)降低到O(1),从而大大提高了防火墙的吞吐量。