著者
Suzuki Shinichi Shinjo Yasushi Hirotsu Toshio Itano Kozo Kato Kazuhiko
出版者
Elsevier Ltd.
雑誌
Journal of Network and Computer Applications (ISSN:10848045)
巻号頁・発行日
vol.30, no.4, pp.1275-1282, 2007-11
被引用文献数
5 2

In conventional egress network access control (NAC) based on access control lists (ACLs),modifying the ACLs is a heavy task for administrators. To enable configuration without a largeamount of administrators’ effort, we introduce capabilities to egress NAC. In our method, a user cantransfer his/her access rights (capabilities) to other persons without asking administrators. To realizeour method, we use a DNS cache server and a router. A resolver of the client sends the user name,domain name, and service name to the DNS cache server. The DNS server issues capabilitiesaccording to a policy and sends them to the client. The client puts these capabilities into the IP optionsof packets and sends them to the router. The router verifies the capabilities, and determines whether topass or block the packets. In this paper, we describe the design and implementation of our method indetail. Experimental results show that our method does not reduce the router’s performance.