Programmable In-Network Security for Context-aware BYOD Policies

dc.contributor.advisorChen, Angen_US
dc.creatorKang, Qiaoen_US
dc.date.accessioned2021-01-29T14:40:51Zen_US
dc.date.available2021-01-29T14:40:51Zen_US
dc.date.created2021-05en_US
dc.date.issued2021-01-26en_US
dc.date.submittedMay 2021en_US
dc.date.updated2021-01-29T14:40:51Zen_US
dc.description.abstractBring Your Own Device (BYOD) has become the new norm in enterprise networks, but BYOD security remains a top concern. Context-aware security, which enforces access control based on dynamic runtime context, is a promising approach. Recent work has developed SDN solutions to collect device contexts and enforce access control at a central controller. However, the central controller could become a bottleneck and attack target. Responding to context changes from the remote controller is also too slow for real-time decision change. We present a new paradigm, programmable in-network security (Poise), which is enabled by the emergence of programmable switches. At the heart of Poise is a novel security primitive, which can be programmed to support a wide range of contextaware policies in hardware. Users of Poise specify concise policies, and Poise compiles them into different configurations of the primitive in P4. Compared to traditional SDN defenses, Poise is resilient to control plane saturation attacks, and it dramatically increases defense agility.en_US
dc.format.mimetypeapplication/pdfen_US
dc.identifier.citationKang, Qiao. "Programmable In-Network Security for Context-aware BYOD Policies." (2021) Master’s Thesis, Rice University. <a href="https://hdl.handle.net/1911/109786">https://hdl.handle.net/1911/109786</a>.en_US
dc.identifier.urihttps://hdl.handle.net/1911/109786en_US
dc.language.isoengen_US
dc.rightsCopyright is held by the author, unless otherwise indicated. Permission to reuse, publish, or reproduce the work beyond the bounds of fair use or other exemptions to copyright law must be obtained from the copyright holder.en_US
dc.subjectBYODen_US
dc.subjectaccess controlen_US
dc.subjectprogrammable data planesen_US
dc.titleProgrammable In-Network Security for Context-aware BYOD Policiesen_US
dc.typeThesisen_US
dc.type.materialTexten_US
thesis.degree.departmentComputer Scienceen_US
thesis.degree.disciplineEngineeringen_US
thesis.degree.grantorRice Universityen_US
thesis.degree.levelMastersen_US
thesis.degree.nameMaster of Scienceen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
KANG-DOCUMENT-2021.pdf
Size:
1.96 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 2 of 2
No Thumbnail Available
Name:
PROQUEST_LICENSE.txt
Size:
5.84 KB
Format:
Plain Text
Description:
No Thumbnail Available
Name:
LICENSE.txt
Size:
2.6 KB
Format:
Plain Text
Description: