Bands: An inter-domain internet security policy management system for IPSEC/VPN

被引:2
|
作者
Yang, YY [1 ]
Fu, ZJ [1 ]
Wu, SF [1 ]
机构
[1] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
关键词
inter-domain security management; security policy management; IPSecNPN;
D O I
10.1109/INM.2003.1194183
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IPSec/VPN is widely deployed for users to remotely access their corporate data. IPSec policies must be correctly set up for VPN to provide anticipated protection. Manual policy setup is unscalable, inefficient and error-prone. Automated policy generation to comply with and enforce high-level security policies is desired but difficult, especially in an inter-domain environment when a VPN traverse multiple domains. This paper presents a distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation. The BANDS architecture consists of two phases: AS (Autonomous System) route path discovery and an inter-domain collaborative protocol for policy negotiation among the autonomous systems discovered in the first phase. Each AS conceptually has one security requirement server responsible for the task of inter-domain policy negotiation. Following this two-step process in BANDS, a set of distributed, security policies (for the implementation of policy enforcement) will be automatically negotiated/generated based on decentralized and predefined security requirements.
引用
收藏
页码:231 / 244
页数:14
相关论文
共 50 条
  • [1] SEM: A Security Evaluation Model for Inter-domain Routing System in the Internet
    Liu, Xin
    Zhu, Peidong
    Peng, Yuxing
    IP OPERATIONS AND MANAGEMENT, PROCEEDINGS, 2008, 5275 : 142 - 153
  • [2] A security architecture for TMN inter-domain management
    Gagnon, F
    Maillot, D
    Olnes, J
    Hofseth, L
    Sacks, L
    INTELLIGENCE IN SERVICES AND NETWORKS: TECHNOLOGY FOR COOPERATIVE COMPETITION, 1997, 1238 : 417 - 426
  • [3] IPsec/VPN security policy correctness and assurance
    Yang, Yanyan
    Martel, Charles U.
    Fu, Zhi
    Wu, Shyhtsun Felix
    JOURNAL OF HIGH SPEED NETWORKS, 2006, 15 (03) : 275 - 289
  • [4] Security and integrity requirements across inter-domain management
    Maillot, D
    Olnes, J
    Ordy, OE
    Rao, S
    GLOBAL INFORMATION INFRASTRUCTURE (GII) EVOLUTION: INTERWORKING ISSUES, 1996, : 478 - 492
  • [5] Internet Inter-Domain Traffic
    Labovitz, Craig
    Iekel-Johnson, Scott
    McPherson, Danny
    Oberheide, Jon
    Jahanian, Farnam
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2010, 40 (04) : 75 - 86
  • [6] ROUSSEAU: A monitoring system for inter-domain routing security
    Deng, Wenping
    Zhu, Peidong
    Lu, Xicheng
    CNSR 2008: PROCEEDINGS OF THE 6TH ANNUAL COMMUNICATION NETWORKS AND SERVICES RESEARCH CONFERENCE, 2008, : 255 - +
  • [7] Stabilizing inter-domain routing in the Internet
    Chen, Y
    Datta, AK
    Tixeuil, S
    EURO-PAR 2002 PARALLEL PROCESSING, PROCEEDINGS, 2002, 2400 : 749 - 752
  • [8] Stabilizing inter-domain routing in the Internet
    Chen, Y
    Datta, AK
    Tixeuil, S
    JOURNAL OF HIGH SPEED NETWORKS, 2005, 14 (01) : 21 - 37
  • [9] Inter-Domain Route Diversity for the Internet
    Misseri, Xavier
    Gojmerac, Ivan
    Rougier, Jean-Louis
    NETWORKING 2012 WORKSHOPS, 2012, 7291 : 63 - 71
  • [10] An IPSec Mediation Approach for Safe Establishment of Inter-domain VPNs
    Matos, Alexandre
    Matos, Fernando
    Simoes, Paulo
    Monteiro, Edmundo
    IP OPERATIONS AND MANAGEMENT, PROCEEDINGS, 2009, 5843 : 155 - 160