BANDS: An inter-domain internet security policy management system for IPSEC/VPN

Research output: Chapter in Book/Report/Conference proceedingConference contribution

19 Citations (Scopus)

Abstract

IPSec/VPN is widely deployed for users to remotely access their corporate data. IPSec policies must be correctly set up for VPN to provide anticipated protection. Manual policy setup is unscalable, inefficient and error-prone. Automated policy generation to comply with and enforce high-level security policies is desired but difficult, especially in an inter-domain environment when a VPN traverse multiple domains. This paper presents a distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation. The BANDS architecture consists of two phases: AS (Autonomous System) route path discovery and an inter-domain collaborative protocol for policy negotiation among the autonomous systems discovered in the first phase. Each AS conceptually has one security requirement server responsible for the task of inter-domain policy negotiation. Following this two-step process in BANDS, a set of distributed security policies (for the implementation of policy enforcement) will be automatically negotiated/generated based on decentralized and predefined security requirements.

Original languageEnglish
Title of host publicationIntegrated Network Management VIII
Subtitle of host publicationManaging It All - IFIP/IEEE 8th International Symposium on Integrated Network Management, IM 2003
PublisherSpringer New York LLC
Pages231-244
Number of pages14
ISBN (Print)9781475755213
DOIs
Publication statusPublished - 2003
EventIFIP/IEEE 8th International Symposium on Integrated Network Management, IM 2003 - Colorado Springs, CO, United States
Duration: 2003 Mar 242003 Mar 28

Publication series

NameIFIP Advances in Information and Communication Technology
Volume118
ISSN (Print)1868-4238

Conference

ConferenceIFIP/IEEE 8th International Symposium on Integrated Network Management, IM 2003
Country/TerritoryUnited States
CityColorado Springs, CO
Period03-03-2403-03-28

All Science Journal Classification (ASJC) codes

  • Information Systems and Management

Fingerprint

Dive into the research topics of 'BANDS: An inter-domain internet security policy management system for IPSEC/VPN'. Together they form a unique fingerprint.

Cite this