A Distributed Dynamic µFirewall Architecture with Mobile Agents and KeyNote Trust Management System

  • Authors:
  • Hai Jin;Feng Xian;Zongfen Han;Shengli Li

  • Affiliations:
  • -;-;-;-

  • Venue:
  • ICICS '02 Proceedings of the 4th International Conference on Information and Communications Security
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to end-to-end design principle in distributed applications, many emerging security problems could not be solved by conventional security technologies, such as firewalls and IDSs. To address these problems, we present a distributed dynamic 碌Firewall architecture based on mobile agents and Key-Note trust management system. In this architecture, KeyNote trust management system provides the scalable distributed control capability and supports a mechanism called "policy-updates on demand". Mobile agents implement dynamic security policy reconfiguration and enhance the scalability. Each 碌Firewall is built with a packet filter and DTE-enhanced evaluator to enforce policy at the end points. A distributed intrusion detection and response (DIDR) system supports dynamic security capabilities and provides fast response to attacks from all possible sources. Our architecture is scalable, topology independent, and intrusion-tolerant.