Skip to main navigation Skip to search Skip to main content

IPSec/VPN security policy: Correctness, conflict detection, and resolution

  • Zhi Fu
  • , S. Felix Wu
  • , He Huang
  • , Kung Loh
  • , Fengmin Gong
  • , Ilia Baldine
  • , Chong Xu

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

IPSec (Internet Security Protocol Suite) functions will be executed correctly only if its policies are correctly specified and configured. Manual IPSec policy configuration is inefficient and error-prone. An erroneous policy could lead to communication blockade or serious security breach. In addition, even if policies are specified correctly in each domain, the diversified regional security policy enforcement can create significant problems for end-to-end communication because of interaction among policies in different domains. A policy management system is, therefore, demanded to systematically manage and verify various IPSec policies in order to ensure an end-to-end security service. This paper contributes to the development of an IPSec policy management system in two aspects. First, we defined a high-level security requirement, which not only is an essential component to automate the policy specification process of transforming from security requirements to specific IPSec policies but also can be used as criteria to detect conflicts among IPSec policies, i.e. policies are correct only if they satisfy all requirements. Second, we developed mechanisms to detect and resolve conflicts among IPSec policies in both intradomain and inter-domain environment.

Original languageEnglish
Title of host publicationPolicies for Distributed Systems and Networks - International Workshop, POLICY 2001, Proceedings
EditorsMorris Sloman, Emil C. Lupu, Jorge Lobo
PublisherSpringer Verlag
Pages39-56
Number of pages18
ISBN (Print)3540416102
DOIs
Publication statusPublished - 2001
EventInternational Workshop on Policies for Distributed Systems and Networks, POLICY 2001 - Bristol, United Kingdom
Duration: 2001 Jan 292001 Jan 31

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume1995
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Workshop on Policies for Distributed Systems and Networks, POLICY 2001
Country/TerritoryUnited Kingdom
CityBristol
Period01-01-2901-01-31

All Science Journal Classification (ASJC) codes

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'IPSec/VPN security policy: Correctness, conflict detection, and resolution'. Together they form a unique fingerprint.

Cite this