Show simple item record

dc.contributor.authorNaous, Jad
dc.contributor.authorStutsman, Ryan
dc.contributor.authorMazieres, David
dc.contributor.authorMcKeown, Nick
dc.contributor.authorZeldovich, Nickolai
dc.date.accessioned2011-11-10T16:31:07Z
dc.date.available2011-11-10T16:31:07Z
dc.date.issued2009-08
dc.identifier.isbn9781605584430
dc.identifier.urihttp://hdl.handle.net/1721.1/67004
dc.description.abstractNetwork security is gravitating towards more centralized control. Strong centralization places a heavy burden on the administrator who has to manage complex security policies and be able to adapt to users' requests. To be able to cope, the administrator needs to delegate some control back to end-hosts and users, a capability that is missing in today's networks. Delegation makes administrators less of a bottleneck when policy needs to be modified and allows network administration to follow organizational lines. To enable delegation, we propose ident++ - a simple protocol to request additional information from end-hosts and networks on the path of a flow. ident++ allows users and end-hosts to participate in network security enforcement by providing information that the administrator might not have or rules to be enforced on their behalf. In this paper we describe ident++ and how it provides delegation and enables flexible and powerful policies.en_US
dc.description.sponsorshipUnited States. Dept. of Homeland Security (Scholarship and Fellowship Program)en_US
dc.description.sponsorshipUnited States. Dept. of Energyen_US
dc.description.sponsorshipOak Ridge Institute for Science and Educationen_US
dc.language.isoen_US
dc.publisherAssociation for Computing Machineryen_US
dc.relation.isversionofhttp://dx.doi.org/10.1145/1592681.1592685en_US
dc.rightsCreative Commons Attribution-Noncommercial-Share Alike 3.0en_US
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/3.0/en_US
dc.sourceMIT web domainen_US
dc.titleDelegating Network Security with More Informationen_US
dc.typeArticleen_US
dc.identifier.citationNaous, Jad et al. “Delegating network security with more information.” in WREN '09, Proceedings of the 1st ACM workshop on Research on enterprise networking, August 21, 2009, Barcelona, Spain, ACM Press.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratoryen_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Scienceen_US
dc.contributor.approverZeldovich, Nickolai
dc.contributor.mitauthorZeldovich, Nickolai
dc.relation.journalProceedings of the 1st ACM Workshop on Research on Enterprise Networking, WREN '09en_US
dc.eprint.versionAuthor's final manuscripten_US
dc.type.urihttp://purl.org/eprint/type/ConferencePaperen_US
dspace.orderedauthorsNaous, Jad; Stutsman, Ryan; Mazieres, David; McKeown, Nick; Zeldovich, Nickolaien
dc.identifier.orcidhttps://orcid.org/0000-0003-0238-2703
mit.licenseOPEN_ACCESS_POLICYen_US
mit.metadata.statusComplete


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record