跳至主導覽 跳至搜尋 跳過主要內容

IPSec/VPN security policy: Correctness, conflict detection, and resolution

  • Zhi Fu
  • , S. Felix Wu
  • , He Huang
  • , Kung Loh
  • , Fengmin Gong
  • , Ilia Baldine
  • , Chong Xu

研究成果: Conference contribution

60   連結會在新分頁中開啟 引文 斯高帕斯(Scopus)

摘要

IPSec (Internet Security Protocol Suite) functions will be executed correctly only if its policies are correctly specified and configured. Manual IPSec policy configuration is inefficient and error-prone. An erroneous policy could lead to communication blockade or serious security breach. In addition, even if policies are specified correctly in each domain, the diversified regional security policy enforcement can create significant problems for end-to-end communication because of interaction among policies in different domains. A policy management system is, therefore, demanded to systematically manage and verify various IPSec policies in order to ensure an end-to-end security service. This paper contributes to the development of an IPSec policy management system in two aspects. First, we defined a high-level security requirement, which not only is an essential component to automate the policy specification process of transforming from security requirements to specific IPSec policies but also can be used as criteria to detect conflicts among IPSec policies, i.e. policies are correct only if they satisfy all requirements. Second, we developed mechanisms to detect and resolve conflicts among IPSec policies in both intradomain and inter-domain environment.

原文English
主出版物標題Policies for Distributed Systems and Networks - International Workshop, POLICY 2001, Proceedings
編輯Morris Sloman, Emil C. Lupu, Jorge Lobo
發行者Springer Verlag
頁面39-56
頁數18
ISBN(列印)3540416102
DOIs
出版狀態Published - 2001
事件International Workshop on Policies for Distributed Systems and Networks, POLICY 2001 - Bristol, United Kingdom
持續時間: 2001 1月 292001 1月 31

出版系列

名字Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
1995
ISSN(列印)0302-9743
ISSN(電子)1611-3349

Conference

ConferenceInternational Workshop on Policies for Distributed Systems and Networks, POLICY 2001
國家/地區United Kingdom
城市Bristol
期間01-01-2901-01-31

All Science Journal Classification (ASJC) codes

  • 理論電腦科學
  • 一般電腦科學

指紋

深入研究「IPSec/VPN security policy: Correctness, conflict detection, and resolution」主題。共同形成了獨特的指紋。

引用此