TCP-AuthN: An approach to dynamic firewall operation in grid environments

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Autorschaft

  • Jan Wiebelitz
  • Christopher Kunz
  • Stefan Piger
  • Christian Grimm
Forschungs-netzwerk anzeigen

Details

OriginalspracheEnglisch
Titel des SammelwerksProceedings of the 5th International Conference on Networking and Services, ICNS 2009
Seiten481-486
Seitenumfang6
PublikationsstatusVeröffentlicht - 2009
Veranstaltung5th International Conference on Networking and Services, ICNS 2009 - Valencia, Spanien
Dauer: 20 Apr. 200925 Apr. 2009

Publikationsreihe

NameProceedings of the 5th International Conference on Networking and Services, ICNS 2009

Abstract

Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

ASJC Scopus Sachgebiete

Zitieren

TCP-AuthN: An approach to dynamic firewall operation in grid environments. / Wiebelitz, Jan; Kunz, Christopher; Piger, Stefan et al.
Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. S. 481-486 4976806 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009).

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Wiebelitz, J, Kunz, C, Piger, S & Grimm, C 2009, TCP-AuthN: An approach to dynamic firewall operation in grid environments. in Proceedings of the 5th International Conference on Networking and Services, ICNS 2009., 4976806, Proceedings of the 5th International Conference on Networking and Services, ICNS 2009, S. 481-486, 5th International Conference on Networking and Services, ICNS 2009, Valencia, Spanien, 20 Apr. 2009. https://doi.org/10.1109/ICNS.2009.35
Wiebelitz, J., Kunz, C., Piger, S., & Grimm, C. (2009). TCP-AuthN: An approach to dynamic firewall operation in grid environments. In Proceedings of the 5th International Conference on Networking and Services, ICNS 2009 (S. 481-486). Artikel 4976806 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009). https://doi.org/10.1109/ICNS.2009.35
Wiebelitz J, Kunz C, Piger S, Grimm C. TCP-AuthN: An approach to dynamic firewall operation in grid environments. in Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. S. 481-486. 4976806. (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009). doi: 10.1109/ICNS.2009.35
Wiebelitz, Jan ; Kunz, Christopher ; Piger, Stefan et al. / TCP-AuthN : An approach to dynamic firewall operation in grid environments. Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. S. 481-486 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009).
Download
@inproceedings{84303ef6f4434cdc9297919d85128c66,
title = "TCP-AuthN: An approach to dynamic firewall operation in grid environments",
abstract = "Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.",
author = "Jan Wiebelitz and Christopher Kunz and Stefan Piger and Christian Grimm",
year = "2009",
doi = "10.1109/ICNS.2009.35",
language = "English",
isbn = "9780769535869",
series = "Proceedings of the 5th International Conference on Networking and Services, ICNS 2009",
pages = "481--486",
booktitle = "Proceedings of the 5th International Conference on Networking and Services, ICNS 2009",
note = "5th International Conference on Networking and Services, ICNS 2009 ; Conference date: 20-04-2009 Through 25-04-2009",

}

Download

TY - GEN

T1 - TCP-AuthN

T2 - 5th International Conference on Networking and Services, ICNS 2009

AU - Wiebelitz, Jan

AU - Kunz, Christopher

AU - Piger, Stefan

AU - Grimm, Christian

PY - 2009

Y1 - 2009

N2 - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

AB - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

UR - http://www.scopus.com/inward/record.url?scp=67650675834&partnerID=8YFLogxK

U2 - 10.1109/ICNS.2009.35

DO - 10.1109/ICNS.2009.35

M3 - Conference contribution

AN - SCOPUS:67650675834

SN - 9780769535869

T3 - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009

SP - 481

EP - 486

BT - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009

Y2 - 20 April 2009 through 25 April 2009

ER -