Skip to main content

Conference Paper

MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy

Iffat Anjum, Jessica Sokal, Hafiza Ramzah Rehman, Ben Weintraub, Ethan Leba, William Enck, Cristina Nita-Rotaru, and Bradley Reaves

Proceedings of the ACM Symposium on Access Control Models and Technologies, 2023

Extends NetViews policy enforcement to geographically distributed sites with roaming users.

Abstract

Commercially-available software defined networking (SDN) technologies will play an important role in protecting the on-premises resources that remain as enterprises transition to zero trust architectures. However, existing solutions assume the entire network resides in a single geographic location, requiring organizations with multiple sites to manually ensure consistency of security policy across all sites. In this paper, we present MSNetViews, which extends a single, globally-defined and managed, enterprise network security policy to many geographically distributed sites. Each site operates independently and enforces a site-specific policy slice that is dynamically parameterized with user location as employees roam between sites. We build a prototype of MSNetViews and show that for an enterprise with globally distributed sites, the average time for policy state to settle after a user roams to a new site is well below two seconds. As such, we demonstrate that multisite organizations can efficiently protect their on-premises network-attached devices via a single global perspective.

Citation (IEEE)

I. Anjum, J. Sokal, H. R. Rehman, B. Weintraub, E. Leba, W. Enck, C. Nita-Rotaru, and B. Reaves, “MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy,” in Proceedings of the ACM Symposium on Access Control Models and Technologies, 2023.

BibTeX
@inproceedings{asr+23,
  author = {Anjum, Iffat and Sokal, Jessica and {Hafiza Ramzah Rehman} and Weintraub, Ben and Leba, Ethan and Enck, William and Nita-Rotaru, Cristina and {Bradley Reaves}},
  booktitle = {Proceedings of the ACM Symposium on Access Control Models and Technologies},
  date = {2023-06},
  title = {{MSNetViews}: Geographically Distributed Management of Enterprise Network Security Policy},
}