loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
16th Annual Computer Security Applications Conference (ACSAC'00)
Policy-based Authentication and Authorization: Secure Access to the Network Infrastructure
New Orleans, Louisiana
December 11-December 15
ISBN: 0-7695-0859-6
Jeff Hayes, Alcatel IND
A gaping hole in many of today's networks is the weak security surrounding the network devices themselves--the routers, the switches, and the access servers. In all public networks and in some private networks, the network devices are shared virtually among different user communities. Access to the configuration schemes and command lines is most often an "all or nothing" proposition--the network administrator gets either read-only privileges or read/write privileges. In this case, authentication equals authorization. Herein lies the problem.Security policies may mandate certain administrators have read-only capabilities for all device parameters and read / write capabilities for a certain subset of commands. Each administrator may have a unique access profile. Authentication verifies identity.Authorization verifies privileges. This paper will address the value of using a centralized provisioned management structure that disseminates network policies and administration privileges to all the devices that make up the network infrastructure.
Citation:
Jeff Hayes, "Policy-based Authentication and Authorization: Secure Access to the Network Infrastructure," acsac, pp.328, 16th Annual Computer Security Applications Conference (ACSAC'00), 2000
Usage of this product signifies your acceptance of the Terms of Use.