Virtualized dynamic port assignment and windowed whitelisting for securing infrastructure servers

2016 IEEE International Conference on Electro Information Technology (EIT)(2016)

引用 2|浏览3
暂无评分
摘要
We describe a novel method of securing services by adding windowed whitelisting to an arbitrary and constantly changing assignment of services to ports (or virtual ports). This is aimed at mitigating port scanning threats and unauthorized intrusion attempts, and to protect a community of known users from data loss. In essence, port numbers, time, and IP address will be used as part of the password/access mechanism; this segregates traffic so that content-based restrictions can be more effective. It also provides a connection-based security wrapper for services that might be vulnerable to software exploits, such as the buffer overruns and backdoors. The method requires a portal to authenticate users and disseminate knowledge of the current port assignment, in addition to permitting users to request a “window” of time to be white-listed. It requires a firewall with dynamic port and whitelist reconfigurability. The method is intended to enhance byte frequency histogram analysis and regexp restriction of traffic. It also requires a policy for keeping alive long-lasting connections. It can be implemented easily with virtual ports using redirection. We discuss some implications for web page rewriting and cgi security, as well as legacy services such as ssh and sftp. The effect is to create a cross-product of IP range, port range, and time specificity, to create a large and sparse search space for any adversary.
更多
查看译文
关键词
virtualized dynamic port assignment,windowed whitelisting,infrastructure servers,service security,port scanning threats mitigation,unauthorized intrusion attempts,data loss,port numbers,IP address,password/access mechanism,content-based restrictions,connection-based security wrapper,software exploits,buffer overruns,user authentication,knowledge dissemination,firewall,whitelist reconfigurability,byte frequency histogram analysis,regexp restriction,Web page rewriting,cgi security,IP range,port range,time specificity,Web service
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要