A secure Web-based global management system for firewall/VPN devices

被引:1
作者
Choi, MJ [1 ]
Hong, JWK [1 ]
机构
[1] Pohang Univ Sci & Technol, Dept Comp Sci & Engn, Pohang, South Korea
关键词
firewall; VPN; global management; secure communication; SNMP; MIB; Web-based management system;
D O I
10.1109/JCN.2002.6596935
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A firewall is a security device placed between a private network and a public network such as the Internet. It is designed to protect the private network resources from unauthorized user access. Today, various firewalls are widely used in many places (e.g., Internet data centers, company headquarters, branch office, telecommuters' homes). What is desperately needed is a management system that can easily configure, monitor and manage multisite deployed firewalls from a central location. For flexibility, such a management system must be divided into components and needs to use an open management protocol, such as the Simple Network Management Protocol (SNMP). Yet the SNMP has a security defect. Further, the proposed standard Management Information Base (MIB) for firewalls is insufficient for supporting centralized global management of a lot of firewall devices. In this paper, we present the design and implementation of a secure Web and SNMP-based global firewall management system. We have focused on two aspects: 1) extending the existing proposed standard MIB to support the configuration and monitoring of hundreds or thousands of firewall and VPN devices; 2) providing secure communication among global manager system components in order to provide secure firewall management. We also present our work on developing our firewall global manager (FGM) on commercial firewal/VPN devices.
引用
收藏
页码:71 / 78
页数:8
相关论文
共 29 条
[1]  
[Anonymous], 1998, RFC2409
[2]  
[Anonymous], 2000, INTERNET REQUEST COM
[3]  
*ATM NETW, BROADB INT GAT BIG
[4]  
BLUMENTHAL, 1998, RFC2274
[5]  
Case J., 1990, 1157 RFC
[6]  
CHAPMAN DB, 1996, BUILDING INTERNET FI
[7]  
CHERITON, 1996, INT SOC S NETW DISTR
[8]  
Cheswick WilliamR., 1994, FIREWALLS INTERNET S
[9]  
*CISCO, PIX FIR MAN
[10]  
COOPER M, 2000, OVERVIEW INTRUSION D