Protection of components based on a smart-card enhanced security module

  • Authors:
  • Joaquín García-Alfaro;Sergio Castillo;Jordi Castellà-Roca;Guillermo Navarro;Joan Borrell

  • Affiliations:
  • DEIC-UAB, Bellaterra (Catalonia), Spain;DEIC-UAB, Bellaterra (Catalonia), Spain;DEiM-ETSE-URV, Tarragona (Catalonia), Spain;DEIC-UAB, Bellaterra (Catalonia), Spain;DEIC-UAB, Bellaterra (Catalonia), Spain

  • Venue:
  • CRITIS'06 Proceedings of the First international conference on Critical Information Infrastructures Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present in this paper the use of a security mechanism to handle the protection of network security components, such as Firewalls and Intrusion Detection Systems. Our approach consists of a kernel-based access control method which intercepts and cancels forbidden system calls launched by a potential remote attacker. This way, even if the attacker gains administration permissions, she will not achieve her purpose. To solve the administration constraints of our approach, we use a smart-card based authentication mechanism for ensuring the administrator's identity. Through the use of a cryptographic protocol, the protection mechanism verifies administrator's actions before holding her the indispensable privileges to manipulate a component. Otherwise, the access control enforcement will come to its normal operation. We also show in this paper an overview of the implementation of this mechanism on a research prototype, developed for GNU/Linux systems, over the Linux Security Modules (LSM) framework.