
The use of security policy enforcement mechanisms has been a topic in recent literature. Particular focus has been on the class of policies that can be enforced by these mechanisms but not on the security policy guiding the execution of the monitoring mechanisms. It has been a challenge to enforce information confidentiality in a multi-level secure system since malicious users can exploit covert channels within the enforcement mechanisms to propagate confidential information. In this paper, we characterize necessary security properties for an enforcement mechanism that can ensure secure execution of the untrusted programs even though they may be malicious.
Ad-hoc networking is a relatively new operating mode for rapid mobile host interconnection. However, it suffers from the lack of a fixed infrastructure that forces each adhoc host to rely on each other, in order to maintain the network stability and functionality. This singularity of adhoc networks introduces several issues, most of which concern the system’s security. This paper focuses on investigating the security threats of ad-hoc networks together with their unique ability to meet specific emergency requirements, such as the rapid deployment of emergency networks which can enhance and optimize the disaster relief efforts after a natural disaster or a terrorist attack. Moreover this particular type of networks can be found very efficient in military environments where the cellular/PCS services may not be available. Considering the difficulty of establishing a secure network where the impacted group members share no prior electronic information, and moreover considering how this can be achieved through the most reliable, secure and efficient way, we propose a new protocol for dynamic multiparty password key agreement, based on Elliptic Curve Cryptography.
Almost all current anti spam measures are reactive, filtering being the most common. But to react means always to be one step behind. Reaction requires to predict the next action of the attacker. So the focus on fighting spam should rather be on prevention. Current proposals focus on fixing SMTP's lack of authentication, but introduce two new major problems: First, all current attempts break existing SMTP functionality and, second, it seems to be hardly possible to enforce a change of SMTP world wide. Therefore other preventive measures should be implemented. The most promising approach is to prevent spammers from collecting email addresses. Several proposals show ways to obfuscate addresses on web pages and to create HTTP tar pits in order to catch spammers' harvesters. In our previous work, we combined a HTTP tar pit with a SMTP tar pit and found it to be very effective in trapping harvesters. Here, we extend the use of the combined tar pit to identify harvesters and to dynamically block access to web pages for harvesters, because of the combined tar pit's high efficiency. We present a test setup to validate the effectiveness of our tool. As the experiment is still running, we can only report on preliminary findings so far.
Nowadays the protection of information against unauthorized disclosure, transfer, modification, or destruction, whether accidental or intentional, is a very important issue that concerns the information society. The scope of this paper is to develop a Contactless Smartcard protocol, which will be able operate securely and effectively, under a variety of attack methods. The system implements a novel mutual authentication procedure between a Contactless Reader and a Smartcard, calculates securely the corresponding parameters, and protects the system against malicious attacks. The system can be used in a wide spectrum of applications that require simplicity, ease of use, long life, low cost and portability. Suitable applications could be, Electronic Payments, Public Transport Electronic Fare, Highway toll payments, Medical Applications, and Access Control.
The rapid emergence of GPS enabled devices, sensors and mobile equipment in commercial as well as government organizations has led to considerable research in timeand location-based access control schemes. Location-based access policies enhance the security of an application by restricting access to an object only from specified locations. On the other hand, temporal constraints provide granularity in security features and also limit damage to an application to a specific time interval (e.g. when staff are present to respond if necessary). This paper introduces a novel approach to locationand time-based access control mechanism using Role-Based Access Control (RBAC). We believe that it is well-suited for organizations that require timeand location-based access control over static or mobile objects.
An XML firewall differs from a conventional firewall because its major task is to control access to web services rather than to filter untrusted addresses. An XML firewall can effectively protect web services from being attacked by inspecting a complete XML message including its head and data segments, and rejecting unauthorized web services invocation. In this paper, we propose a formal XML firewall security model using role-based access control (RBAC). Our proposed model supports user authentication and user authorization according to information stored in a user database and a policy database associated with an XML firewall. The formal model is designed compositionally using Petri nets, which can serve as a high-level design for XML firewall implementation. The key components of our compositional security model are the application model and the XML firewall model. To illustrate the advantages of our formal approach, we use an existing Petri net tool to verify some key properties of our model, such as boundedness and liveness.
The Extensible Authentication Protocol (EAP) is a kind of Esperanto used for access control in various network technologies such as WLAN or VPN. We introduce the trusted EAP module, a tamper resistant chip that computes the EAP protocol. Its functional interface is compatible with IETF emerging specifications. We present an open smartcard platform which enables the design of cheap components, both on client and server side; furthermore we describe a management model that remotely modifies embedded credentials and applications. An implementation of a RADIUS server working with EAP server modules is detailed and analyzed. Finally experimental performances are commented and we underline that today EAP modules compute complex protocol like EAP-TLS in less than 5s, and therefore may be deployed in existing networks.
There are many essential applications for quorum systems in ad-hoc networks, such as that of location servers in large-scale networks. Existing research proposes many approaches to the problems, many of which are incomplete, cumbersome, or incur significant cost. We describe and analyse a self-organising quorum system that creates an emergent intelligence to minimise overhead and maximise survivability. We then examine the quorum.s performance as a location server and suggest improvements to the query mechanism and routing algorithm using the information.
The security vulnerabilities in software systems can be categorized by either the cause or severity. Several software vulnerabilities datasets for major operating systems and web servers are examined. The goal is to identify the attributes of each category that can potentially be exploited for enhancing security.
After the ARP and IP were drafted, a subtle weakness in the Address Resolution Protocol was discovered. Unlike TCP, ARP relies on raw sockets and like UDP; ARP provides no means to establish the authenticity of the source of incoming packets. Although this problem can be resolved in case of UDP packets by considering alternate approaches such as DNS replies being sent over TCP rather than UDP using the DNSSEC architecture so that false DNS replies may not be accepted by a host; ARP is still prone to similar attacks. This paper identifies known weaknesses of the ARP and analyses the impact of a network flooding utility developed by us, the underlying ideology of which is this very weakness of the ARP. The purpose of our implementation is to extend what conventional tools can do, by incorporating a network flooding module in it, and to simulate a flooded network where hosts are forced to broadcast outgoing packets to the entire network. In some network conditions, the gateway may also be brought into broadcast mode, leading to undesired results. Various attack strategies are considered and the network performance during these attacks is measured. We also reveal a strategy by which ICMP replies are received by a host trying to PING a destination, but the host fails to recognize these replies. Such a weakness in the ICMP can lead to erroneous network management.
Joon Son and Jim Alves-FossCenter for Secure and Dependable SystemsUniversity of IdahoPOBOX 441008 Moscow, ID 83844-1008email: [son2320,jimaf]@uidaho.eduABSTRACTReal-time systems must satisfy timing constraints. In ourprevious work, we showed that a covert timing channelcannot be completely closed in some system configura-tions due to the timing constraints imposed by the Rate-Monotonic (RM) real-time scheduling algorithm. In thispaper, we construct a probabilistic model to measure twoquantities of a covert timing channel in RM based systems:channel capacity and quantity of specific information. Weshow how these two metrics can be calculated from ourprobabilistic model and why they are useful metrics in eval-uation of a covert (timing) channel.KEYWORDSCovert timing channel capacity, quantity of specific infor-mation, Rate-Monotonic scheduling.
This paper presents our on-going project on performance evaluation of the major existing solutions based on server- side access control for SYN-flooding distributed denial- of-service attacks using a real network system. Although many solutions have been proposed and implemented, there is no formal performance study that measures and compares the solutions based on server-side access control. The successful connection rate of the existing solutions was measured, compared and analyzed using an experiment test bed developed by LINUX-based PCs. We have tested SYN-cookie, Random Drop and the unmodified TCP in various conditions. We also simulated different types of legitimate clients in the end-to-end signal propagation delay to evaluate the fairness in connections. The results of our experiments showed that SYN-cookie resulted in the perfect (i.e., 100%) connection rate in all the experiments and configurations. Regardless of the length of the end-to-end delay, the connection rate of the unmodified TCP dropped to below 5% for a low request rate of 50 requests per second or more. Random Drop was more effective in improving connection rate than the unmodified TCP if the end-to-end delay was short or when the TCP backlog queue size was increased to more then 300 slots. KEY WORDS Network security, access control, denial-of-service attacks, TCP SYN-flood attacks, flash crowd