(PDF) Network Access Control Technology-Proposition To Contain New Security Challenges
(PDF) Network Access Control Technology-Proposition To Contain New Security Challenges
Authors:
Abdelmajid Lakbabi
Figures
+1
Public Full-text 1
Received June 11, 2012; revised July 31, 2012; accepted August 12, 2012
ABSTRACT
Traditional products working independently are no longer sufficient, since threats are continually gaining in complexity,
diversity and performance; In order to proactively block such threats we need more integrated information security so-
lution. To achieve this objective, we will analyze a real-world security platform, and focus on some key components
Like, NAC, Firewall, and IPS/IDS then study their interaction in the perspective to propose a new security posture that
coordinate and share security information between different network security components, using a central policy server
that will be the NAC server or the PDP (the Policy Decision Point), playing an orchestration role as a central point of
control. Finally we will conclude with potential research paths that will impact NAC technology evolution.
Keywords: Threats; NAC; Identity; Security Posture; Policy Enforcement Point; Remediation; Coordination;
Orchestration.
discuss their respective weaknesses, and then study how flow as described below in Figure 3
NAC can play a fundamental role, to improve network Cisco NAC access decision is based on:
security by extending its capabilities to administer net- Users, their devices, and their roles in the network
work access requests based on NAC capabilities, and Evaluate whether machines are compliant with secu-
integrating legacy security products, and existing net- rity policies
work infrastructure. Enforce security policies by blocking, isolating, and
repairing noncompliant machines
2.1.2. Technical Description of Cisco and Juniper Provide easy and secure guest access
NAC
Audit and report whom is on the network
2.1.2.1. Cisco Network Access Admission Overview Enforcement Points (where the access decision is ap-
Cisco NAC mechanism is based on the following process plied)
View
View
View
View full-text
Article
W. Cha · D. Won
Read more
Article
Read more
Article
Read more
Company
About us
News
Careers
Support
Help Center
Business solutions
Advertising
Recruiting
Advertisement
© 2008-2023 ResearchGate GmbH. All rights reserved.