...
首页> 外文期刊>IEEE Communications Magazine >Taxonomy of conflicts in network security policies
【24h】

Taxonomy of conflicts in network security policies

机译:网络安全策略中的冲突分类

获取原文
获取原文并翻译 | 示例

摘要

Network security polices are essential elements in Internet security devices that provide traffic filtering, integrity, confidentiality, and authentication. Network security perimeter devices such as firewalls, IPSec, and IDS/IPS devices operate based on locally configured policies. However, configuring network security policies remains a complex and error-prone task due to rule dependency semantics and the interaction between policies in the network. This complexity is likely to increase as the network size increases. A successful deployment of a network security system requires global analysis of policy configurations of all network security devices in order to avoid policy conflicts and inconsistency. Policy conflicts may cause serious security breaches and network vulnerability such as blocking legitimate traffic, permitting unwanted traffic, and insecure data transmission. This article presents a comprehensive classification of security policy conflicts that might potentially exist in a single security device (intrapolicy conflicts) or between different network devices (interpolicy conflicts) in enterprise networks. We also show the high probability of creating such conflicts even by expert system administrators and network practitioners.
机译:网络安全策略是Internet安全设备中的基本元素,可提供流量过滤,完整性,机密性和身份验证。网络安全外围设备(如防火墙,IPSec和IDS / IPS设备)基于本地配置的策略运行。但是,由于规则依赖性语义以及网络中策略之间的交互,配置网络安全策略仍然是一项复杂且容易出错的任务。随着网络规模的增加,这种复杂性可能会增加。网络安全系统的成功部署需要对所有网络安全设备的策略配置进行全局分析,以避免策略冲突和不一致。策略冲突可能会导致严重的安全漏洞和网络漏洞,例如阻止合法流量,允许不需要的流量以及不安全的数据传输。本文介绍了安全策略冲突的全面分类,该冲突可能存在于单个安全设备(内部冲突)或企业网络中不同网络设备之间(策略间冲突)。我们还展示了即使由专家系统管理员和网络从业人员也极有可能造成此类冲突。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号