Cenet-- capability enabled networking: towards least-privileged networking

Update Item Information
Publication Type thesis
School or College College of Engineering
Department Computing
Author Joseph, Jithu
Title Cenet-- capability enabled networking: towards least-privileged networking
Date 2015
Description In today's IP networks, any host can send packets to any other host irrespective of whether the recipient is interested in communicating with the sender or not. The downside of this openness is that every host is vulnerable to an attack by any other host. We ob- serve that this unrestricted network access (network ambient authority) from compromised systems is also a main reason for data exfiltration attacks within corporate networks. We address this issue using the network version of capability based access control. We bring the idea of capabilities and capability-based access control to the domain of networking. CeNet provides policy driven, fine-grained network level access control enforced in the core of the network (and not at the end-hosts) thereby removing network ambient authority. Thus CeNet is able to limit the scope of spread of an attack from a compromised host to other hosts in the network. We built a capability-enabled SDN network where communication privileges of an endpoint are limited according to its function in the network. Network capabilities can be passed between hosts, thereby allowing a delegation-oriented security policy to be realized. We believe that this base functionality can pave the way for the realization of sophisticated security policies within an enterprise network. Further we built a policy manager that is able to realize Role-Based Access Control (RBAC) policy based network access control using capability operations. We also look at some of the results of formal analysis of capability propagation models in the context of networks.
Type Text
Publisher University of Utah
Subject Access control in SDN; Capability based access control; Network access control; Network security; Security; Software defined networks
Dissertation Name Master of Science in Computer Science
Language eng
Rights Management ©Jithu Joseph
Format Medium application/pdf
Format Extent 27,310 bytes
Identifier etd3/id/3990
ARK ark:/87278/s6jq489k
Setname ir_etd
ID 197540
Reference URL https://collections.lib.utah.edu/ark:/87278/s6jq489k