16th Annual Computer Security Applications Conference (ACSAC'00)
Secure compartmented data access over an untrusted network using a COTS-based architecture
New Orleans, Louisiana
December 11-December 15
ISBN: 0-7695-0859-6
We present an approach to secure compartmented data access over an untrusted network using a secure network computing architecture. We describe the architecture and show how application-level firewalls and other commercial-off-the-shelf (COTS) products may be used to implement compartmentalized access to sensitive information and to provide access control over an untrusted network and in a variety of environments. Security-related issues and assumptions are discussed. We compare our architecture to other models of controlling access to sensitive data and draw conclusions about the requirements for high-security solutions for electronic business as well as DoD applications.
Index Terms:
telecommunication security; computer networks; authorisation; software architecture; electronic commerce; military computing; secure compartmented data access; untrusted network; COTS-based architecture; secure network computing architecture; application-level firewalls; commercial-off-the-shelf products; sensitive information; access control; sensitive data; electronic business; DoD applications; military applications
Citation:
P.C. Clark, M.C. Meissner, K.O. Vance, "Secure compartmented data access over an untrusted network using a COTS-based architecture," acsac, pp.217, 16th Annual Computer Security Applications Conference (ACSAC'00), 2000