SysFlow: Toward a Programmable Zero Trust Framework for System Security

SysFlow: Toward a Programmable Zero Trust Framework for System Security
复制标题

DOI:
10.1109/tifs.2023.3264152
复制
发表时间:
2023
影响因子:
6.8
通讯作者:
Sungmin Hong;Lei Xu;Jianwei Huang;Hongda Li;Hongxin Hu;G. Gu
Sungmin Hong;Lei Xu;Jianwei Huang;Hongda Li;Hongxin Hu;G. Gu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Sungmin Hong;Lei Xu;Jianwei Huang;Hongda Li;Hongxin Hu;G. Gu

文献摘要

被引文献

相似文献

零信任是现代基础设施中网络安全范式的新兴趋势(例如,企业,云,边缘,物联网和5G),将安全防御措施从基于静态和周边的控制系统转移到关注的用户和资源,而无需假设隐性信任。但是,当前的零信任体系结构(ZTA)主要关注网络安全性,并且缺乏对系统级安全策略和抽象的深入考虑,这使得原理的实现不完整。为了弥合差距,我们提出了一个创新的可编程系统安全框架,称为SYS Flow,以启用系统资源的统一,动态和细粒度的零信任安全控制。 SYS Flow引入了一种新型的系统流抽象,以模拟整个基础架构的系统活动,并提供系统级数据平面以及控制平面的分离和抽象。新的逻辑集中式控制器可容纳一个统一的可编程策略决策点(PDP),该策略决策点(PDP)通过将可编程的安全策略转换为系统流量规则,从而获得了用于控制系统资源访问的系统行为的整体视图。 SYS流数据平面充当策略执行点(PEP),执行翻译的系统流量规则,可以动态更新并促进细粒度的响应式动作。我们的广泛评估表明,系统流的有效性和可扩展性,该问题在各种情况下以较小的性能开销解决了安全问题。
Zero Trust, as an emerging trend of cybersecurity paradigms in modern infrastructure (e.g., enterprise, cloud, edge, IoT, and 5G), is moving security defenses from static and perimeter-based control systems to focus on users and resources with no assumption of implicit trust. However, the current Zero Trust Architecture (ZTA) mainly focuses on the network security and lacks in-depth considerations on system-level security policies and abstractions, which leaves the realization of the principle incomplete. To bridge the gap, we propose an innovative programmable system security framework called SYS FLOW to enable unified, dynamic, and fine-grained Zero Trust security control for system resources. SYS FLOW introduces a novel system flow abstraction to model system activities across the entire infrastructure, and provides a system-level data plane and control plane separation and abstraction. The new logically centralized controller accommodates a unified programmable Policy Decision Point (PDP) that acquires a holistic view of system behaviors for controlling system resource accesses by translating programmable security policies into system flow rules. The SYS FLOW data plane, acting as Policy Enforcement Point (PEP), enforces translated system flow rules, which can be updated dynamically and facilitate fine-grained responsive actions. Our extensive evaluations demonstrate the effectiveness and scalability of SYS FLOW, which addresses the security issues in various scenarios with a minor performance overhead.