A new language could improve home computer security

September 18, 2009

Korean computer scientists have developed a security policy specification for home networks that could make us more secure from cyber attack in our homes. They report details in the International Journal of Ad Hoc and Ubiquitous Computing.

Companies, banks, and other organizations take internet security very seriously and usually have firewalls and IT departments to protect them from attack as a matter of course. Domestic and small office networks are just as vulnerable to hacking, malicious , worms, viruses, and eavesdropping. An attack can wreak havoc on individuals and small businesses when security it compromised.

With home and small office networks connecting all kinds of devices - personal computers, mobile devices, remote security cameras, gaming consoles, and more - they represent an even more heterogeneous mix than many larger offices.

Now, Geon Woo Kim of the Electronics and Telecommunications Research Institute, in Korea, and colleagues there and at Kyungpook National University, have developed a specification for security policy on home networks that can guarantee reliability and availability. The specification also takes into account authentication, authorization, security policy deployment so that all users in the home are not only protected from malware but also can help ensure everyone can use the network when they need to.

Kim and his team explain that home networks most commonly have only a single gateway from the internet. Every packet of information must pass through this gateway at the border between the home network and the internet. It should act as a core component providing all security. "Whenever a new access to the home network is found, it should be able to authenticate and authorize it and enforce the security policy based on rules set by the home administrator," the team says.

However, to make such an approach effective but simple requires a way to consistently describe and specify the security policy. The computer scientists first turned to a computer markup language, eXtensible Access Control Markup Language (XACML). XACML is a general purpose language and so it lacks the notation for security policies and authorization rules. The team has now developed a related language - Home security Description Language, xHDL - that includes the necessary notation for securing a home network.

The new language consists of seven elements: combining-rule element, authentication element, user element, object element, object-group element, role element, and rule elements. Each of these terms within xHDL could be used to run a browser-based control centre. That program would provide the domestic administrator with simple control options to allow access to the home network only for specific devices and to control the packets of information that can pass through the gateway to and from the internet.

More information: "Security policy specification for home network" in Int. J. Ad Hoc and Ubiquitous Computing, 2009, 4, 372-378

Source: Inderscience Publishers (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3 /5 (4 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • GrayMouser - Sep 18, 2009
    • Rank: not rated yet
    Well, a good start would be getting away from C based languages. They were created for a specific type of programming (portable assembler) and are poor for programming-in-the-large and high reliability programming. Those CAN be done in C & C++ but the burden is placed on the programmer who often doesn't have the time, tools, or inclination to prove their programs to be free of errors that other languages don't allow.
  • Foolish1 - Sep 19, 2009
    • Rank: not rated yet
    Pushing intelligence out to the gateway is not a workable solution to the stated problem.

    Neither has the act of defining policy been a salient barrier to implementing security. The central hard issue to be addressed is how best to save users from themselves.

September 18, 2009 all stories

Comments: 2

3 /5 (4 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • NEC's World's First Security Configuration Analyzing System Enables Automatic Detection of Network Security Problems
    created May 16, 2005 | popularity not rated yet | comments 0
  • IIJ releases quarantine for corporate PCs
    created Nov 08, 2005 | popularity not rated yet | comments 0
  • Cisco CEO to use 'holistic' security
    created Feb 17, 2006 | popularity not rated yet | comments 0
  • Wireless-security campaign steps up
    created Mar 08, 2006 | popularity not rated yet | comments 0
  • UK government launches the IT Security Awareness for Everyone website
    created Feb 25, 2005 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Calling Gnuplot from FORTRAN
    created 1hour ago
  • Help with a camera choice
    created Nov 18, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • More from Physics Forums - Computing & Technology

Other News

The websites of Bing, Microsoft and Yahoo

Australia, Canada approve Yahoo!-Microsoft deal

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

Australian and Canadian competition authorities have approved the Internet search and advertising partnership between Yahoo! and Microsoft, the companies said Tuesday.


Google, Yahoo zero in on Internet 'freedom' bill

Technology / Internet

created 16 minutes ago | popularity not rated yet | comments 0

Google Inc. and other Internet companies have zeroed in on a resilient effort by a Republican lawmaker to pass legislation that could restrict their ability to take a nuanced approach to operating in "repressive" foreign ...


Google apologizes for offensive first lady image

Technology / Internet

created 46 minutes ago | popularity not rated yet | comments 0

(AP) -- Google Inc. is apologizing for a racially offensive image of the First Lady that appears at the top of the list when users search for pictures of Michelle Obama on its site.


Selling chip makers on optical computing

Selling chip makers on optical computing

Technology / Semiconductors

created 5 hours ago | popularity 5 / 5 (5) | comments 0

(PhysOrg.com) -- Computer chips that transmit data with light instead of electricity consume much less power than conventional chips, but so far, they've remained laboratory curiosities. Professors Vladimir ...


Facebook creates dual-class structure, but no IPO (AP)

Facebook creates dual-class structure, but no IPO

Technology / Business

created 1hour ago | popularity 1 / 5 (1) | comments 0

(AP) -- Facebook has created a dual-class stock structure designed to give founder Mark Zuckerberg and other existing shareholders control over the company.