首页> 外文学位 >An integrated approach for security on demand in high-speed, shared-use networks.
【24h】

An integrated approach for security on demand in high-speed, shared-use networks.

机译:一种用于高速共享使用网络中按需安全性的集成方法。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation presents a user level security on demand system, resulting from an integration of a fundamental framework for network security with the fundamental and unique characteristics of Asynchronous Transfer Mode (ATM) networks. The framework offers a conceptual structure encapsulating the fundamental knowledge and set of relationships in network security, permitting systematic and scientific reasoning about network security. The changing nature of networks from a set of unconnected entities, controlled and used by a specific class of users, to an increasingly interconnected and integrated, “mixed use”, set of networks, simultaneously shared by different classes of users, requires a mechanism to enable these “mixed use” networks to meet the diverse security requirements of all users. The framework, developed as a part of this dissertation, provides the ability for all user groups, such as the military, government, industry and academia, to define their security requirements within its context and enable the framework, when integrated into an ATM network, to provide a template for matching network security resources to individual user requirements.; The user level aspect of the security system is unique and is enabled by the ATM network's call setup process. In this approach, during the call setup phase, the security posture of every node and link is computed, utilizing the security framework. When the system configures a virtual path from source to destination, every node and link is verified to meet the user specified security, in addition to bandwidth and other quality of service (QoS) requirements. Traffic is launched when the call setup succeeds, otherwise, the call fails. Thus, the approach is consistent with the basic characteristics of ATM networks, offering comprehensive security while viewing security as a distributed network resource, allocating it to each user efficiently, based on demand and dictated by the need. This approach was modeled for representative, 50, 40 and 32 node ATM networks and the model is successfully implemented through an asynchronous distributed simulation. Analysis of the behavior, obtained utilizing stochastic, representative input traffic, scientifically validates the security on demand system and reveals negligible performance impact on an ATM network's operation and advantages over the status quo.
机译:本文提出了一种基于用户级别的按需安全系统,它是基于网络安全的基本框架与异步传输模式(ATM)网络的基本和独特特性的集成而产生的。该框架提供了一个概念性结构,封装了网络安全的基本知识和关系集,允许对网络安全进行系统和科学的推理。网络的性质不断变化,从一组由特定类别的用户控制和使用的未连接实体,到越来越多的互连和集成的“混合使用”,由不同类别的用户同时共享的一组网络,需要一种机制来使这些“混合使用”网络能够满足所有用户的多样化安全要求。该框架是本论文的一部分,它为军事,政府,工业和学术界等所有用户群体提供了在其上下文中定义其安全要求的能力,并在将其集成到ATM网络中后使其能够运行,提供用于将网络安全资源匹配到各个用户需求的模板;安全系统的用户级别方面是唯一的,并由ATM网络的呼叫建立过程启用。在这种方法中,在呼叫建立阶段,利用安全框架计算每个节点和链路的安全状态。当系统配置从源到目标的虚拟路径时,除了带宽和其他服务质量(QoS)要求之外,还将验证每个节点和链接是否满足用户指定的安全性。呼叫建立成功后,将启动流量,否则呼叫将失败。因此,该方法与ATM网络的基本特征是一致的,它提供全面的安全性,同时将安全性视为分布式网络资源,根据需求和需要将其有效地分配给每个用户。该方法是针对代表性的50、40和32节点ATM网络建模的,并且该模型通过异步分布式仿真成功实现。通过使用随机的代表性输入流量获得的行为分析,科学地验证了按需安全系统,并揭示了对ATM网络运行的性能影响可忽略不计,以及与现状相比的优势。

著录项

  • 作者

    Schumacher, Henry Jerold.;

  • 作者单位

    Arizona State University.;

  • 授予单位 Arizona State University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 1999
  • 页码 145 p.
  • 总页数 145
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号