TCP-AuthN: An approach to dynamic firewall operation in grid environments

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Authors

  • Jan Wiebelitz
  • Christopher Kunz
  • Stefan Piger
  • Christian Grimm
View graph of relations

Details

Original languageEnglish
Title of host publicationProceedings of the 5th International Conference on Networking and Services, ICNS 2009
Pages481-486
Number of pages6
Publication statusPublished - 2009
Event5th International Conference on Networking and Services, ICNS 2009 - Valencia, Spain
Duration: 20 Apr 200925 Apr 2009

Publication series

NameProceedings of the 5th International Conference on Networking and Services, ICNS 2009

Abstract

Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

ASJC Scopus subject areas

Cite this

TCP-AuthN: An approach to dynamic firewall operation in grid environments. / Wiebelitz, Jan; Kunz, Christopher; Piger, Stefan et al.
Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. p. 481-486 4976806 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009).

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Wiebelitz, J, Kunz, C, Piger, S & Grimm, C 2009, TCP-AuthN: An approach to dynamic firewall operation in grid environments. in Proceedings of the 5th International Conference on Networking and Services, ICNS 2009., 4976806, Proceedings of the 5th International Conference on Networking and Services, ICNS 2009, pp. 481-486, 5th International Conference on Networking and Services, ICNS 2009, Valencia, Spain, 20 Apr 2009. https://doi.org/10.1109/ICNS.2009.35
Wiebelitz, J., Kunz, C., Piger, S., & Grimm, C. (2009). TCP-AuthN: An approach to dynamic firewall operation in grid environments. In Proceedings of the 5th International Conference on Networking and Services, ICNS 2009 (pp. 481-486). Article 4976806 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009). https://doi.org/10.1109/ICNS.2009.35
Wiebelitz J, Kunz C, Piger S, Grimm C. TCP-AuthN: An approach to dynamic firewall operation in grid environments. In Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. p. 481-486. 4976806. (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009). doi: 10.1109/ICNS.2009.35
Wiebelitz, Jan ; Kunz, Christopher ; Piger, Stefan et al. / TCP-AuthN : An approach to dynamic firewall operation in grid environments. Proceedings of the 5th International Conference on Networking and Services, ICNS 2009. 2009. pp. 481-486 (Proceedings of the 5th International Conference on Networking and Services, ICNS 2009).
Download
@inproceedings{84303ef6f4434cdc9297919d85128c66,
title = "TCP-AuthN: An approach to dynamic firewall operation in grid environments",
abstract = "Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.",
author = "Jan Wiebelitz and Christopher Kunz and Stefan Piger and Christian Grimm",
year = "2009",
doi = "10.1109/ICNS.2009.35",
language = "English",
isbn = "9780769535869",
series = "Proceedings of the 5th International Conference on Networking and Services, ICNS 2009",
pages = "481--486",
booktitle = "Proceedings of the 5th International Conference on Networking and Services, ICNS 2009",
note = "5th International Conference on Networking and Services, ICNS 2009 ; Conference date: 20-04-2009 Through 25-04-2009",

}

Download

TY - GEN

T1 - TCP-AuthN

T2 - 5th International Conference on Networking and Services, ICNS 2009

AU - Wiebelitz, Jan

AU - Kunz, Christopher

AU - Piger, Stefan

AU - Grimm, Christian

PY - 2009

Y1 - 2009

N2 - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

AB - Grid computing provides users with transparent access to substantial compute and storage resources. Up to now the main focus lay in the development of Grid infrastructures and the development of services providing access to Grid resources. This leads to a negligence of security aspects, which, for example, leads to the recommendation of open wide port ranges on firewalls protecting the Grid resources. In this paper we present an approach for a dynamic firewall operation facilitated by a strong inline authentication for every TCP connection. The presented approach, which is based on X.509 certificates and public-key encryption uses TCP segments exchanged during the TCP three-way handshake between the client and the server to transport user authentication information. Firewalls on the path use this authentication information to authorize the connection. To distinguish the authentication information in the TCP segments from application data a new TCP option tcpauthn is introduced.

UR - http://www.scopus.com/inward/record.url?scp=67650675834&partnerID=8YFLogxK

U2 - 10.1109/ICNS.2009.35

DO - 10.1109/ICNS.2009.35

M3 - Conference contribution

AN - SCOPUS:67650675834

SN - 9780769535869

T3 - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009

SP - 481

EP - 486

BT - Proceedings of the 5th International Conference on Networking and Services, ICNS 2009

Y2 - 20 April 2009 through 25 April 2009

ER -