{"id":"https://openalex.org/W1811337449","doi":"https://doi.org/10.1109/discex.2003.1194883","title":"The STRONGMAN architecture","display_name":"The STRONGMAN architecture","publication_year":2004,"publication_date":"2004-03-02","ids":{"openalex":"https://openalex.org/W1811337449","doi":"https://doi.org/10.1109/discex.2003.1194883","mag":"1811337449"},"language":"en","primary_location":{"id":"doi:10.1109/discex.2003.1194883","is_oa":false,"landing_page_url":"https://doi.org/10.1109/discex.2003.1194883","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings DARPA Information Survivability Conference and Exposition","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://repository.upenn.edu/cgi/viewcontent.cgi?article=1039&context=cis_papers","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5023057383","display_name":"Angelos D. Keromytis","orcid":"https://orcid.org/0000-0003-3815-5932"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"A.D. Keromytis","raw_affiliation_strings":["CS Department, Columbia University, USA","Department of Computer Science , Columbia University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"CS Department, Columbia University, USA","institution_ids":["https://openalex.org/I78577930"]},{"raw_affiliation_string":"Department of Computer Science , Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109897169","display_name":"Sotiris Ioannidis","orcid":"https://orcid.org/0009-0002-0682-0475"},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"S. Ioannidis","raw_affiliation_strings":["CIS Department, University of Pennsylvania, USA","#N#               * University of Pennsylvania"],"affiliations":[{"raw_affiliation_string":"CIS Department, University of Pennsylvania, USA","institution_ids":["https://openalex.org/I79576946"]},{"raw_affiliation_string":"#N#               * University of Pennsylvania","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008794446","display_name":"Michael B. Greenwald","orcid":null},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"M.B. Greenwald","raw_affiliation_strings":["CIS Department, University of Pennsylvania, USA","#N#               * University of Pennsylvania"],"affiliations":[{"raw_affiliation_string":"CIS Department, University of Pennsylvania, USA","institution_ids":["https://openalex.org/I79576946"]},{"raw_affiliation_string":"#N#               * University of Pennsylvania","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5104018094","display_name":"Jonathan M. Smith","orcid":"https://orcid.org/0000-0003-3309-6603"},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"J.M. Smith","raw_affiliation_strings":["CIS Department, University of Pennsylvania, USA","#N#               * University of Pennsylvania"],"affiliations":[{"raw_affiliation_string":"CIS Department, University of Pennsylvania, USA","institution_ids":["https://openalex.org/I79576946"]},{"raw_affiliation_string":"#N#               * University of Pennsylvania","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5023057383"],"corresponding_institution_ids":["https://openalex.org/I78577930"],"apc_list":null,"apc_paid":null,"fwci":5.0177,"has_fulltext":false,"cited_by_count":49,"citation_normalized_percentile":{"value":0.9519395,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"178","last_page":"188"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9969000220298767,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.7765179872512817},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7686348557472229},{"id":"https://openalex.org/keywords/enforcement","display_name":"Enforcement","score":0.6568300127983093},{"id":"https://openalex.org/keywords/firewall","display_name":"Firewall (physics)","score":0.6307251453399658},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.596877932548523},{"id":"https://openalex.org/keywords/security-policy","display_name":"Security policy","score":0.5480409860610962},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.5442992448806763},{"id":"https://openalex.org/keywords/application-firewall","display_name":"Application firewall","score":0.5399790406227112},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5124309659004211},{"id":"https://openalex.org/keywords/ipsec","display_name":"IPsec","score":0.455514132976532},{"id":"https://openalex.org/keywords/autonomy","display_name":"Autonomy","score":0.4431546628475189},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.4364956021308899},{"id":"https://openalex.org/keywords/single-point-of-failure","display_name":"Single point of failure","score":0.43207675218582153},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.40215662121772766},{"id":"https://openalex.org/keywords/stateful-firewall","display_name":"Stateful firewall","score":0.31835412979125977},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.10017141699790955},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.08948269486427307},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.08276918530464172}],"concepts":[{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.7765179872512817},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7686348557472229},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.6568300127983093},{"id":"https://openalex.org/C77714075","wikidata":"https://www.wikidata.org/wiki/Q5452017","display_name":"Firewall (physics)","level":5,"score":0.6307251453399658},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.596877932548523},{"id":"https://openalex.org/C154908896","wikidata":"https://www.wikidata.org/wiki/Q2167404","display_name":"Security policy","level":2,"score":0.5480409860610962},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.5442992448806763},{"id":"https://openalex.org/C86444895","wikidata":"https://www.wikidata.org/wiki/Q451816","display_name":"Application firewall","level":4,"score":0.5399790406227112},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5124309659004211},{"id":"https://openalex.org/C67396069","wikidata":"https://www.wikidata.org/wiki/Q210214","display_name":"IPsec","level":3,"score":0.455514132976532},{"id":"https://openalex.org/C65414064","wikidata":"https://www.wikidata.org/wiki/Q484105","display_name":"Autonomy","level":2,"score":0.4431546628475189},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.4364956021308899},{"id":"https://openalex.org/C165136773","wikidata":"https://www.wikidata.org/wiki/Q1363179","display_name":"Single point of failure","level":2,"score":0.43207675218582153},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.40215662121772766},{"id":"https://openalex.org/C22927095","wikidata":"https://www.wikidata.org/wiki/Q1784206","display_name":"Stateful firewall","level":3,"score":0.31835412979125977},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.10017141699790955},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.08948269486427307},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.08276918530464172},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C115304011","wikidata":"https://www.wikidata.org/wiki/Q72755","display_name":"Schwarzschild radius","level":3,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C2776401274","wikidata":"https://www.wikidata.org/wiki/Q3756855","display_name":"Accretion (finance)","level":2,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C10138342","wikidata":"https://www.wikidata.org/wiki/Q43015","display_name":"Finance","level":1,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C183915046","wikidata":"https://www.wikidata.org/wiki/Q1316152","display_name":"Charged black hole","level":4,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.0}],"mesh":[],"locations_count":5,"locations":[{"id":"doi:10.1109/discex.2003.1194883","is_oa":false,"landing_page_url":"https://doi.org/10.1109/discex.2003.1194883","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings DARPA Information Survivability Conference and Exposition","raw_type":"proceedings-article"},{"id":"pmh:oai:repository.upenn.edu:cis_papers-1039","is_oa":true,"landing_page_url":"https://repository.upenn.edu/cis_papers/39","pdf_url":"https://repository.upenn.edu/cgi/viewcontent.cgi?article=1039&context=cis_papers","source":{"id":"https://openalex.org/S4306402083","display_name":"ScholarlyCommons (University of Pennsylvania)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79576946","host_organization_name":"University of Pennsylvania","host_organization_lineage":["https://openalex.org/I79576946"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Departmental Papers (CIS)","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.5.2866","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.5.2866","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www1.cs.columbia.edu/~angelos/Papers/strongman.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.7.7339","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.7.7339","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"ftp://ftp.cis.upenn.edu/pub/mbgreen/papers/discex03.ps.gz","raw_type":"text"},{"id":"pmh:oai:repository.upenn.edu:20.500.14332/6435","is_oa":false,"landing_page_url":"https://repository.upenn.edu/handle/20.500.14332/6435","pdf_url":null,"source":{"id":"https://openalex.org/S4377196331","display_name":"Scholarly Commons (University of Pennsylvania)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79576946","host_organization_name":"University of Pennsylvania","host_organization_lineage":["https://openalex.org/I79576946"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"published","raw_type":"Presentation"}],"best_oa_location":{"id":"pmh:oai:repository.upenn.edu:cis_papers-1039","is_oa":true,"landing_page_url":"https://repository.upenn.edu/cis_papers/39","pdf_url":"https://repository.upenn.edu/cgi/viewcontent.cgi?article=1039&context=cis_papers","source":{"id":"https://openalex.org/S4306402083","display_name":"ScholarlyCommons (University of Pennsylvania)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79576946","host_organization_name":"University of Pennsylvania","host_organization_lineage":["https://openalex.org/I79576946"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Departmental Papers (CIS)","raw_type":"text"},"sustainable_development_goals":[{"score":0.5400000214576721,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W1811337449.pdf","grobid_xml":"https://content.openalex.org/works/W1811337449.grobid-xml"},"referenced_works_count":17,"referenced_works":["https://openalex.org/W53221114","https://openalex.org/W62390653","https://openalex.org/W1491344747","https://openalex.org/W1553478841","https://openalex.org/W1588926155","https://openalex.org/W1624532646","https://openalex.org/W1678529581","https://openalex.org/W1837136310","https://openalex.org/W1860215963","https://openalex.org/W1958859150","https://openalex.org/W2018501701","https://openalex.org/W2130010856","https://openalex.org/W2131378480","https://openalex.org/W2135292514","https://openalex.org/W2166975838","https://openalex.org/W2168535919","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W2009238965","https://openalex.org/W2361515550","https://openalex.org/W2916429898","https://openalex.org/W8359669","https://openalex.org/W2057573940","https://openalex.org/W4363647490","https://openalex.org/W2347324149","https://openalex.org/W2495628081","https://openalex.org/W2583381754","https://openalex.org/W4234975731"],"abstract_inverted_index":{"The":[0,65],"design":[1],"principle":[2,83],"of":[3,59,84,97,109,131,142,148,160,169],"restricting":[4],"local":[5,85,104],"autonomy":[6,105],"only":[7],"where":[8],"necessary":[9],"for":[10,24,34],"global":[11,90,111],"robustness":[12],"has":[13,27],"led":[14],"to":[15,55,79,101,118,144,154],"a":[16,98,110,116,123,170],"scalable":[17],"Internet.":[18],"Unfortunately,":[19],"this":[20],"scalability":[21],"and":[22,36,167],"capacity":[23],"distributed":[25,171],"control":[26],"not":[28],"been":[29],"achieved":[30],"in":[31,163],"the":[32,82,95,107,129,139,146,158,164,184],"mechanisms":[33,48],"specifying":[35],"enforcing":[37],"security":[38,47,91,112],"policies.":[39,92],"This":[40],"shortcoming":[41],"must":[42],"be":[43],"overcome":[44],"if":[45],"end-to-end":[46],"(such":[49],"as":[50,63],"IPsec":[51],"or":[52],"TLS)":[53],"are":[54],"ever":[56],"replace":[57],"solutions":[58],"short-term":[60],"convenience":[61],"such":[62],"firewalls.":[64],"STRONGMAN":[66],"(for":[67],"Scalable":[68],"Trust":[69],"Of":[70],"Next":[71],"Generation":[72],"Management)":[73],"system":[74],"offers":[75],"three":[76],"new":[77],"approaches":[78,162],"scalability,":[80],"applying":[81],"policy":[86,120],"enforcement":[87,151],"complying":[88],"with":[89],"First":[93],"is":[94,115,138],"use":[96,159],"compliance":[99],"checker":[100],"provide":[102],"great":[103],"within":[106],"constraints":[108],"policy.":[113],"Second":[114],"mechanism":[117],"compose":[119],"rules":[121],"into":[122],"coherent":[124],"enforceable":[125],"set,":[126],"e.g.":[127],"at":[128],"boundaries":[130],"two":[132],"locally":[133],"autonomous":[134],"application":[135],"domains.":[136],"Third":[137],"\"lazy":[140],"instantiation\"":[141],"policies":[143],"reduce":[145],"amount":[147],"state":[149],"that":[150],"points":[152],"need":[153],"maintain.":[155],"We":[156],"demonstrate":[157],"these":[161],"design,":[165],"implementation,":[166],"measurements":[168],"firewall.":[172],"Our":[173],"experiments":[174],"show":[175],"that,":[176],"under":[177],"certain":[178],"circumstances,":[179],"performance":[180],"can":[181],"improve":[182],"over":[183],"traditional-firewall":[185],"approach.":[186]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2018,"cited_by_count":2},{"year":2016,"cited_by_count":1},{"year":2014,"cited_by_count":1},{"year":2013,"cited_by_count":4},{"year":2012,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
