Bands: An inter-domain internet security policy management system for IPSEC/VPN

被引:2
|
作者
Yang, YY [1 ]
Fu, ZJ [1 ]
Wu, SF [1 ]
机构
[1] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
关键词
inter-domain security management; security policy management; IPSecNPN;
D O I
10.1109/INM.2003.1194183
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IPSec/VPN is widely deployed for users to remotely access their corporate data. IPSec policies must be correctly set up for VPN to provide anticipated protection. Manual policy setup is unscalable, inefficient and error-prone. Automated policy generation to comply with and enforce high-level security policies is desired but difficult, especially in an inter-domain environment when a VPN traverse multiple domains. This paper presents a distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation. The BANDS architecture consists of two phases: AS (Autonomous System) route path discovery and an inter-domain collaborative protocol for policy negotiation among the autonomous systems discovered in the first phase. Each AS conceptually has one security requirement server responsible for the task of inter-domain policy negotiation. Following this two-step process in BANDS, a set of distributed, security policies (for the implementation of policy enforcement) will be automatically negotiated/generated based on decentralized and predefined security requirements.
引用
收藏
页码:231 / 244
页数:14
相关论文
共 50 条
  • [31] A cooperative mechanism for inter-domain routing management
    Hu, Ning
    Zou, Peng
    Zhu, Peidong
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2009, 46 (08): : 1251 - 1259
  • [32] Byzantine Robustness for Future Inter-domain Routing Security through Integrated Management Plane
    Tafreshi, Vahid Heydari Famit
    Cruickshank, Haitham
    Sun, Zhili
    2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 820 - 823
  • [33] Inter-domain security management to protect legitimate user access from DDoS attacks
    Kim, Sung Ki
    Min, Byoung Joon
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 2, 2006, 3981 : 876 - 884
  • [34] CENTRALIZED POLICY PROVISIONING FOR INTER-DOMAIN IMS QOS
    Ageal, Mosbah
    Good, Richard
    Elmangosh, Asma
    Ashibani, Majdi
    Ventura, Neco
    Ben-Shatwan, Fathi
    EUROCON 2009: INTERNATIONAL IEEE CONFERENCE DEVOTED TO THE 150 ANNIVERSARY OF ALEXANDER S. POPOV, VOLS 1- 4, PROCEEDINGS, 2009, : 1793 - +
  • [35] Efficient Algorithms for Dynamic Detection and Resolution of IPSec/VPN Security Policy Conflicts
    Niksefat, Salman
    Sabaei, Masoud
    2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2010, : 737 - 744
  • [36] Inter-domain integration of services and service management
    Lewis, D
    Tiropanis, T
    McEwan, A
    Redmond, C
    Wade, V
    Bracht, R
    INTELLIGENCE IN SERVICES AND NETWORKS: TECHNOLOGY FOR COOPERATIVE COMPETITION, 1997, 1238 : 283 - 291
  • [37] Cooperative management framework for inter-domain routing
    Hu, Ning
    Zhu, Pei-Dong
    Zou, Peng
    Wang, Hai-Long
    Tongxin Xuebao/Journal on Communications, 2009, 30 (10 A): : 154 - 160
  • [38] iREX: Efficient inter-domain QoS policy architecture
    Yahaya, Ariffin Datuk
    Harks, Tobias
    Suda, Tatsuya
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [39] Policy aware QoS inter-domain multicast routing
    Costa, A
    Nicolau, MJ
    Santos, A
    Freitas, V
    HPSR 2003: WORKSHOP ON HIGH PERFORMANCE SWITCHING AND ROUTING, 2003, : 275 - 280
  • [40] IRSR: Recover inter-domain routing system from a higher view Beyond internet
    Wang, Yu
    Wang, Zhenxing
    Zhang, Liancheng
    Advances in Intelligent Systems and Computing, 2013, 212 : 505 - 513