loading...
Capability-Based Egress Network Access Control for Transferring Access Rights
Sydney, Australia July 04-July 07
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ICITA.2005.92Third International Conference on Inf ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Shinichi Suzuki, University of Tsukuba
Yasushi Shinjo, University of Tsukuba and JST
Toshio Hirotsu, Toyohashi University of Technology and JST
Kozo Itano, University of Tsukuba and JST
Kazuhiko Kato, University of Tsukuba and JST
In conventional egress network access control (NAC) using access control lists (ACLs), modifying ACLs is a heavy task for administrators. To enable rapid configuration without a large amount of effort by administrators, we introduce capabilities to egress NAC. In our egress NAC, a user can transfer his/her access rights (capabilities) to other persons without asking administrators. To realize capability-based egress NAC, we use DNS messages and IP options to carry capabilities. A resolver of the client sends the user name, domain name, and service name as DNS query messages to a DNS cache server, which issues capabilities according to a policy and sends them as DNS answer messages to the client. The client kernel includes these capabilities in the IP options of packets and sends them to the router. The router checks the capabilities of the packets to determine whether to pass or block them. In this paper, we describe the design and implementation of our method in detail. Experimental results show that our method does not reduce the router?s performance.
Citation:
Shinichi Suzuki, Yasushi Shinjo, Toshio Hirotsu, Kozo Itano, Kazuhiko Kato, "Capability-Based Egress Network Access Control for Transferring Access Rights," icita, vol. 2, pp.488-495, Third International Conference on Information Technology and Applications (ICITA'05) Volume 2, 2005
Usage of this product signifies your acceptance of the Terms of Use.


Suggestions