首页> 外文会议>DARPA Information Survivability Conference Exposition >Domain based Internet security policy management
【24h】

Domain based Internet security policy management

机译:基于域的互联网安全策略管理

获取原文

摘要

As security devices and protocols become widely used on the Internet, the task of managing and processing communication security policies grows steeply in its complexity. This paper presents a scaleable, robust, secure distributed system that can manage communication security policies associated with multiple network domains and resolving the policies - esp. those that specify use of IP-AH/ESP security protocols - into security requirements for inter-domain communication. Technology innovation includes a formal model for IPsec policy specification and resolution, a platform independent policy specification language and a distributed policy server system. The formal model consists of a hierarchical domain model for IPsec policy enforcement and a lattice model of IPsec policy semantics. The policy specification language enables users to specify IPsec policies using the formal model regardless of the make of the security devices. The policy servers maintain the security policies in a distributed database, and negotiate the security associations for protecting inter-domain communication. Both the policy database and the policy exchange protocol are protected from passive and active attacks. Several UNIX implementations are available for non-commercial uses.
机译:随着安全设备和协议在互联网上广泛使用,管理和处理通信安全策略的任务急剧增长其复杂性。本文介绍了可扩展,强大的安全分布式系统,可以管理与多个网络域相关联的通信安全策略并解决策略 - ESP。那些指定IP-AH / ESP安全协议的使用 - 进入域间通信的安全要求。技术创新包括IPsec策略规范和分辨率,平台独立策略规范语言和分布式策略服务器系统的正式模型。正式模型包括用于IPsec策略强制执行的分层域模型和IPSec策略语义的晶​​格模型。策略规范语言使用户能够使用正式模型指定IPSec策略,而不管安全设备的制作。策略服务器在分布式数据库中维护安全策略,并协商用于保护域间通信的安全关联。策略数据库和策略交换协议都受到被动和主动攻击的影响。几种UNIX实现可用于非商业用途。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号