skip to main content
10.1145/1185448.1185569acmotherconferencesArticle/Chapter ViewAbstractPublication Pagesacm-seConference Proceedingsconference-collections
Article

Mobile-driven architecture for managing enterprise security policies

Published:10 March 2006Publication History

ABSTRACT

Authentication, access control, and audit (3As) are three fundamental mechanisms in enterprise security management for countering various types of looming threats from both insiders and outsiders. There has been a variety of web-based or desktop systems implementing those mechanisms, but little supports the applicability of mobile devices in their security management. In this paper we present an approach to managing various types of enterprise security policies using mobile devices in order to effectively monitor and defend trusted domains. Specifically, we describe a security architecture for designing and implementing a mobile-enabled solution for enterprise security management, whereby various benefits such as the backup of important security policies or credentials, offline administration, immediate response, and monitoring, can be achieved. We also present a proof-of-concept implementation using Microsoft Active Directory.

References

  1. J. Bacon, K. Moody, and W. Yao. Access control and trust in the use of widely distributed services. Softw. Pract. Exper., 33(4):375--394, 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. M. Blaze, J. Feigenbaum, J. Ioannidis, and A. D. Keromytis. The KeyNote trust-management system version 2. RFC 2704, September 1999. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. Distributed Management Task Force, Inc. Common Information Model (CIM)-Infrastructure Specification, version 2.3, 2004.Google ScholarGoogle Scholar
  4. Gartner. Extranet Access Management Magic Quadrant, Gartner Research Note (ID: M-13-6853), May 2001.Google ScholarGoogle Scholar
  5. ITU. ITU-T RECOMMENDATION T.128SHARE-APPLICATION SHARING, 1997. ITU-T Q3/16.Google ScholarGoogle Scholar
  6. ITU. ITU-T Recommendation X.509. Information Technology: Open Systems Interconnection - The Directory: Public-Key And Attribute Certificate Frameworks, 2000. ISO/IEC 9594--8.Google ScholarGoogle Scholar
  7. S. Kandala and R. Sandhu. Secure role-based workflow models. In Proceedings of the fifteenth annual working conference on Database and application security, Norwell, MA, USA, 2002. Kluwer Academic Publishers. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. A. Kern, M. Kuhlmann, A. Schaad, and J. Moffett. Observations on the role life-cycle in the context of enterprise security management. In Proceedings of 7th ACM Symposium on Access Control Models and Technologies, Monterey, CA, June 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. G. Neumann and M. Strembeck. A scenario-driven role engineering process for functional RBAC roles. In Proceedings of 7th ACM Symposium on Access Control Models and Technologies, Monterey, CA, June 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. R. L. Rivest and B. Lampson. SDSI - a simple distributed security infrastructure. Technical report, September 1996.Google ScholarGoogle Scholar
  11. H. Roeckle, G. Schimpf, and R. Weidinger. Process-oriented approach for role-finding to implement role-based security administration in a large industrial organization. In Proceedings of 5th ACM Workshop on Role-Based Access Control, Berlin, Germany, July 26-27 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. RSA Security. RSA ClearTrust Advanced User Management Module, 2004.Google ScholarGoogle Scholar
  13. R. Sandhu. Engineering authority and trust in cyberspace: the om-am and rbac way. In Proceedings of 5th ACM Workshop on Role-Based Access Control, pages 71--76, Berlin, Germany, July 26-27 2000. ACM. Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. D. Shin and G.-J. Ahn. A role-based infrastructure management system: Design and implementation. Concurrency and Computation: Practice and Experience, 16(11), August 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. D. Shin, G.-J. Ahn, S. Cho, and S. Jin. On modeling system-centric information for role engineering. In Proceedings of 8th ACM Symposium on Access Control Models and Technologies, Como, Italy, June 2-3 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Mobile-driven architecture for managing enterprise security policies

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Other conferences
        ACM-SE 44: Proceedings of the 44th annual Southeast regional conference
        March 2006
        823 pages
        ISBN:1595933158
        DOI:10.1145/1185448

        Copyright © 2006 ACM

        Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 10 March 2006

        Permissions

        Request permissions about this article.

        Request Permissions

        Check for updates

        Qualifiers

        • Article

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader