The Semantic Firewall
project deals with the enforcement of network security policies
between trust domains in the presence of dynamically changing
and unpredictable Grid communication needs.
The problem is that
whilst traditional static policies allow the type of access mechanisms
required by Grid applications, the same mechansims can be exploited
by crackers for malicious purposes, so firewall policies cannot
remain static for long. By combining conventional Grid security
with semantic reasoning methods, we aim to provide dynamic, adaptive
network security that allows legitimate access but still prevents
unauthorised access.
|