Managing Network Security Policies in Tactical Manet's Using Drama

Abstract

Military networks are required to adapt their access control policies to the Information Operations Condition (INFOCON) levels to minimize the impact of potential malicious activities. Such adaptations must be automated to the extent possible, consistent with mission requirements, and applied network-wide. In this paper, we present a Policy-Based Network Security (PBNS) management approach for tactical MANETs. This approach leverages the DRAMA policy based network management system and the Smart Firewall system to meet the above requirement. It allows administrators to specify low-level network access control policies for each INFOCON level using high-level policies (adapted from the Smart Firewalls approach). The high-level policies are securely distributed to all the policy decision points in the network, which evaluate and enforce policies in a distributed manner. As a consequence of enforcing policies in response to INFOCON level changes, appropriate access control policies will be derived and applied to local firewall devices without human intervention. Thus, operator burden can be significantly reduced and inadvertent errors can be avoided.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Aug 04, 2010
Accession Number
ADA563317

Entities

People

  • Abhrajit Ghosh
  • Chen-Fu Chiang
  • Gary M. Levin
  • Gregory Hadynski
  • Michelle Wolbert
  • Ritu Chadha
  • Yuu-heng Cheng

Tags

DTIC Thesaurus Topics

  • Air Force
  • Air Force Research Laboratories
  • Computer Access Control
  • Computer Network Security
  • Computer Networks
  • Computing System Architectures
  • Detection
  • Information Operations
  • Information Security
  • Intrusion
  • Intrusion Detection
  • Intrusion Detection Systems
  • Intrusion Detectors
  • Military Communications
  • Security
  • Web Service
  • Wireless Networks

Fields of Study

  • Computer science

Readers

  • Aviation Safety Risk Assessment.
  • Computer Networking

Technology Areas

  • Cyber