Bands: An inter-domain internet security policy management system for IPSEC/VPN

被引:2
|
作者
Yang, YY [1 ]
Fu, ZJ [1 ]
Wu, SF [1 ]
机构
[1] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
关键词
inter-domain security management; security policy management; IPSecNPN;
D O I
10.1109/INM.2003.1194183
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IPSec/VPN is widely deployed for users to remotely access their corporate data. IPSec policies must be correctly set up for VPN to provide anticipated protection. Manual policy setup is unscalable, inefficient and error-prone. Automated policy generation to comply with and enforce high-level security policies is desired but difficult, especially in an inter-domain environment when a VPN traverse multiple domains. This paper presents a distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation. The BANDS architecture consists of two phases: AS (Autonomous System) route path discovery and an inter-domain collaborative protocol for policy negotiation among the autonomous systems discovered in the first phase. Each AS conceptually has one security requirement server responsible for the task of inter-domain policy negotiation. Following this two-step process in BANDS, a set of distributed, security policies (for the implementation of policy enforcement) will be automatically negotiated/generated based on decentralized and predefined security requirements.
引用
收藏
页码:231 / 244
页数:14
相关论文
共 50 条
  • [21] Fault management of inter-domain routing
    Zhao, Yinxin
    Yin, Xia
    Wu, Jianping
    Yu, Bin
    2002, Press of Tsinghua University (42): : 60 - 63
  • [22] A modelling technique for inter-domain management
    Seitz, J
    ICC 2000: IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CONFERENCE RECORD, VOLS 1-3: GLOBAL CONVERGENCE THROUGH COMMUNICATIONS, 2000, : 858 - 862
  • [23] Multipath Policy Routing for the Inter-domain Scenario
    Amaral, Pedro
    Bernardo, Luis
    Pinto, Paulo F.
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 3215 - 3221
  • [24] ICS: Interoperable Communication System for Inter-Domain Routing in Internet-of-Things
    Bhavana, A.
    Kumar, Nandha A. N.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (05) : 268 - 275
  • [25] Internet Flattening: Monitoring and Analysis of Inter-Domain Routing
    Xiang, Yang
    Yin, Xia
    Wang, Zhiliang
    Wu, Jianping
    2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,
  • [26] An analysis of Internet inter-domain topology and route stability
    Govindan, R
    Reddy, A
    IEEE INFOCOM '97 - THE CONFERENCE ON COMPUTER COMMUNICATIONS, PROCEEDINGS, VOLS 1-3: SIXTEENTH ANNUAL JOINT CONFERENCE OF THE IEEE COMPUTER AND COMMUNICATIONS SOCIETIES - DRIVING THE INFORMATION REVOLUTION, 1997, : 850 - 857
  • [27] The Mobile Terminal Security Access System Based on IPSec VPN
    Zhao, Di
    He, Xin
    Li, Yunjun
    PROCEEDINGS OF THE 2015 3RD INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND INFORMATION TECHNOLOGY APPLICATIONS, 2015, 35 : 649 - 654
  • [28] Inter-domain security for mobile IPv6
    Laurent-Maknavicius, M
    Bournelle, J
    ANNALS OF TELECOMMUNICATIONS, 2003, 58 (7-8) : 1001 - 1020
  • [29] Inter-domain security for mobile IPv6
    Laurent-Maknavicius, Maryline
    Bournelle, Julien
    2003, Springer Science and Business Media Deutschland GmbH (58): : 7 - 8
  • [30] Inter-domain security for mobile IPv6
    Laurent-Maknavicius, M
    Dupont, F
    ECUMN'2002: 2ND EUROPEAN CONFERENCE ON UNIVERSAL MULTISERVICE NETWORKS, CONFERENCE PROCEEDINGS, 2002, : 238 - 245