Volume 1 Number 1 (Apr. 2006)
Home > Archive > 2006 > Volume 1 Number 1 (Apr. 2006) >
JCP 2006 Vol.1(1): 1-13 ISSN: 1796-203X
doi: 10.4304/jcp.1.1.1-13

Using Firewalls to Enforce Enterprise-wide Policies over Standard Client-Server Interactions

Tuan Phan, Zhijun He, Thu D. Nguyen
1Department of Computer Science, Rutgers University, New Brunswick, USA

Abstract—We propose and evaluate a novel framework for enforcing global coordination and control policies over message passing software components in enterprise computing environments. This framework combines the use of firewalls, both per-node software and dedicated firewalls, with an existing coordination and control system to enforce policies that, among other properties, are stateful and communal. The firewalls act as a set of distributed reference monitors that filter messages exchanged between the interacting software components. The coordination and control system coordinates the firewalls to enforce a specific set of policies, passing only messages allowed by these policies. Filtering decisions may be based on credentials presented to the coordination and control system as well as system state accumulated over time. This filtering approach decouples coordination and control from application implementation, allowing the coordination and control mechanism and application implementations to evolve independently of each other. We demonstrate the power of our framework by using it to specify and enforce an RBAC policy with delegation, revocation, and separation-of-duty over accesses to a cluster of NFS and SMB file servers without changing any client or server implementations. Measurements show that our framework imposes acceptable overheads when enforcing this policy.

Index Terms—coordination and control, access control, reference monitor, firewall, communal policies, stateful policies

[PDF]

Cite: Tuan Phan, Zhijun He, Thu D. Nguyen, "Using Firewalls to Enforce Enterprise-wide Policies over Standard Client-Server Interactions," Journal of Computers vol. 1, no.1, pp. 1-13, 2006.

General Information

ISSN: 1796-203X
Abbreviated Title: J.Comput.
Frequency: Bimonthly
Editor-in-Chief: Prof. Liansheng Tan
Executive Editor: Ms. Nina Lee
Abstracting/ Indexing: DBLP, EBSCO,  ProQuest, INSPEC, ULRICH's Periodicals Directory, WorldCat,etc
E-mail: jcp@iap.org
  • Nov 14, 2019 News!

    Vol 14, No 11 has been published with online version   [Click]

  • Mar 20, 2020 News!

    Vol 15, No 2 has been published with online version   [Click]

  • Dec 16, 2019 News!

    Vol 14, No 12 has been published with online version   [Click]

  • Sep 16, 2019 News!

    Vol 14, No 9 has been published with online version   [Click]

  • Aug 16, 2019 News!

    Vol 14, No 8 has been published with online version   [Click]

  • Read more>>