首页> 外文会议>Large Scale Management of Distributed Systems; Lecture Notes in Computer Science; 4269 >ZERO-Conflict: A Grouping-Based Approach for Automatic Generation of IPSec/VPN Security Policies
【24h】

ZERO-Conflict: A Grouping-Based Approach for Automatic Generation of IPSec/VPN Security Policies

机译:零冲突:一种基于分组的自动生成IPSec / VPN安全策略的方法

获取原文
获取原文并翻译 | 示例

摘要

IPSec/VPN management is a complicated challenge, since IPSec functions correctly only if its security policies satisfy all administrated requirements. Computer-generated security policies tend to conflict with each other, which would causes network congestion or creates security vulnerability. Thus conflict resolving has become an issue. In this paper, a method to automatically generate policies is proposed. Instead of performing complicated conflict-checking procedures as most existing works do, the proposed Zero-Conflict algorithm is able to predict and avoid conflict in advance by using requirement groups and cut points techniques. Since policies are established without the need to perform backward conflict check, thus yielding a significantly less time-complexity, which is O(nlogn). Experimental results show that it maintains a satisfactorily minimal numbers of generated tunnels.
机译:IPSec / VPN管理是一项复杂的挑战,因为IPSec仅在其安全策略满足所有管理要求时才能正常运行。计算机生成的安全策略往往会相互冲突,这将导致网络拥塞或创建安全漏洞。因此,解决冲突已成为一个问题。本文提出了一种自动生成策略的方法。代替大多数现有工作执行复杂的冲突检查程序,建议的零冲突算法能够通过使用需求组和切入点技术来预先预测和避免冲突。由于无需建立后向冲突检查即可建立策略,因此时间复杂度大大降低,为O(nlogn)。实验结果表明,它保持令人满意的最少数量的生成隧道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号