An Automated ACL Generation System for Secure Internal Network

Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura · 2016

Recently, targeted cyber attacks have been sophisticated. In case of such attacks, attackers use dedicated malwares against target organizations. Dedicated malwares slip through the conventional countermeasures, e.g., firewall, intrusion detection systems, and so on, which focus on preventing intrusion of malwares. Against such situation, recent countermeasures focus on the mitigation of damages like information leakage after intrusion. Separated network, e.g., separating internal networks, and controlling access among separated sub-networks, is one of the effective countermeasure. It can prevent malicious communication by malwares, and can easily take countermeasure like isolating of infected hosts. However, we need a lot of cost to construct such network. This paper proposes an automated ACL (Access Control List) generation system for secure internal network. The proposed system refers directory service information and network traffic data, and generates proper access controls based on such information. By using this system, we can construct secure internal network which is applied proper access control easily.

Read the paper · More papers on PaperTik