Poly2 Paradigm: A Secure Network Service Architecture

  • Authors:
  • Eric Bryant;James Early;Rajeev Gopalakrishna;Gregory Roth;Eugene H. Spafford;Keith Watson;Paul Williams;Scott Yost

  • Affiliations:
  • -;-;-;-;-;-;-;-

  • Venue:
  • ACSAC '03 Proceedings of the 19th Annual Computer Security Applications Conference
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

General-purpose operating systems provide a rich computing environmentboth to the user and the attacker. The declining cost ofhardware and the growing security concerns of software necessitatea revalidation of the many assumptions made in network servicearchitectures. Enforcing sound design principles while retainingusability and flexibility is key to practical security. Poly2 is anapproach to build a hardened framework for network services fromcommodity hardware and software. Guided by well-known securitydesign principles such as least common mechanism and economyof mechanism, and driven by goals such as psychological acceptabilityand immediate usability, Poly2 provides a secure platformfor network services. It also serves as a testbed for severalsecurity-related research areas such as intrusion detection, forensics,and high availability. This paper discusses the overall designand philosophy of Poly2, presents an initial implementation, andoutlines future work.