A Metapolicy Framework for Enhancing Domain Expressiveness on the Internet

04/12/2018
by   Gaurav Varshney, et al.
0

Domain Name System (DNS) domains became Internet-level identifiers for entities (like companies, organizations, or individuals) hosting services and sharing resources over the Internet. Domains can specify a set of security policies (such as, email and trust security policies) that should be followed by clients while accessing the resources or services represented by them. Unfortunately, in the current Internet, the policy specification and enforcement are dispersed, non-comprehensive, insecure, and difficult to manage. In this paper, we present a comprehensive and secure metapolicy framework for enhancing the domain expressiveness on the Internet. The proposed framework allows the domain owners to specify, manage, and publish their domain-level security policies over the existing DNS infrastructure. The framework also utilizes the existing trust infrastructures (i.e., TLS and DNSSEC) for providing security. By reusing the existing infrastructures, our framework requires minimal changes and requirements for adoption. We also discuss the initial results of the measurements performed to evaluate what fraction of the current Internet can get benefits from deploying our framework. Moreover, overheads of deploying the proposed framework have been quantified and discussed.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/19/2022

The Quantum Internet: Enhancing Classical Internet Services one Qubit at a Time

Nowadays, the classical Internet has mainly envisioned as the underlying...
research
08/01/2018

Internet of Drones (IoD): Threats, Vulnerability, and Security Perspectives

The development of the Internet of Drones (IoD) becomes vital because of...
research
10/20/2022

A Security and Trust Framework for Decentralized 5G Marketplaces

5G networks intend to cover user demands through multi-party collaborati...
research
08/19/2021

F-PKI: Enabling Innovation and Trust Flexibility in the HTTPS Public-Key Infrastructure

We present F-PKI, an enhancement to the HTTPS public-key infrastructure ...
research
06/29/2018

How Do Tor Users Interact With Onion Services?

Onion services are anonymous network services that are exposed over the ...
research
08/12/2023

On the Security Bootstrapping in Named Data Networking

By requiring all data packets been cryptographically authenticatable, th...
research
03/28/2013

Semantic Matching of Security Policies to Support Security Experts

Management of security policies has become increasingly difficult given ...

Please sign up or login with your details

Forgot password? Click here to reset