首页> 外文学位 >IPsec/VPN security policy engineering: Automatic generation and conflict detection.
【24h】

IPsec/VPN security policy engineering: Automatic generation and conflict detection.

机译:IPsec / VPN安全策略工程:自动生成和冲突检测。

获取原文
获取原文并翻译 | 示例

摘要

IPsec is a useful IP layer security protocol which can provide authentication and encryption for end-to-end traffic flow, but configuring IPsec VPN tunnels is notoriously complicated because it has so many options (key exchange, ciphers, authentication etc) to configure. Thus the ultimate solutions to the security requirements are often prone to errors, let alone that dynamic routing changes can also cause troubles when interacting with existing IPsec tunnels. One minor configuration mistake or one subtle change (e.g. in routing) can cause insecure message transmission or even packet looping.; Therefore, in this dissertation, we first propose a network framework, BANDS, to provide an infrastructure where each domain has a requirement server to correctly handle inter-domain security requirements and policies. It provides a distributed architecture and a negotiation protocol for security policy management across domains.; We also extend the work to automatically, correctly and efficiently generate security policies based on requirements for a linear topology network using the Ordered-Split algorithm, as well as the improved version of the original algorithm (Dynamic Ordered-Split algorithm). They both provide solutions with minimum number of tunnels, while the latter handles better when new requirements come.; Our experiment results acquired during DETER emulations show how interactions between tunnels and routing dynamics can cause serious security problem, so an efficient algorithm to detect security conflicts and tunnel looping that occur among security policies and routing dynamics is also proposed and analyzed to conclude this dissertation.
机译:IPsec是一种有用的IP层安全协议,可以为端到端的流量提供身份验证和加密,但是众所周知,配置IPsec VPN隧道非常复杂,因为它要配置的选项太多(密钥交换,密码,身份验证等)。因此,针对安全性要求的最终解决方案通常容易出错,更不用说动态路由更改也会在与现有IPsec隧道进行交互时引起麻烦。一处小小的配置错误或一处细微的变化(例如,在路由中)可能会导致不安全的消息传输甚至数据包循环。因此,在本文中,我们首先提出一个网络框架BANDS,以提供一个基础结构,其中每个域都有一个需求服务器来正确处理域间安全性需求和策略。它为跨域的安全策略管理提供了分布式体系结构和协商协议。我们还扩展了工作,以使用Ordered-Split算法以及原始算法(Dynamic Ordered-Split算法)的改进版本,根据线性拓扑网络的要求自动,正确且有效地生成安全策略。它们都以最少的隧道数量提供解决方案,而当新的要求出现时,后者可以更好地处理。我们在DETER仿真过程中获得的实验结果表明,隧道与路由动态之间的相互作用如何会导致严重的安全问题,因此,本文还提出了一种有效的算法来检测安全策略和路由动态之间发生的安全冲突和隧道环路,并进行了分析,以得出结论。

著录项

  • 作者

    Yang, Yanyan.;

  • 作者单位

    University of California, Davis.;

  • 授予单位 University of California, Davis.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2006
  • 页码 128 p.
  • 总页数 128
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号