期刊文献+

基于虚拟服务的SSL VPN研究 被引量:15

Research for Virtual Service Based SSL VPN
下载PDF
导出
摘要 基于对标准SSLVPN(SecureSocketLayerVirtualPrivateNetwork)的研究分析,提出了基于虚拟服务的SSLVPN结构.该结构包含两项关键性技术:虚拟服务和基于VPN流的访问控制模型.一方面,通过在客户端动态生成虚拟服务来支持传统应用软件安全透明地访问VPN内部服务群;另一方面,针对VPN流的特点,将访问控制与VPN隧道、转发机制紧耦合,从而实现了细粒度的访问控制及应用层入侵检测.最后,给出了一个实现原型及相关性能测试. Based on the analyses of the standard SSL VPN (Secure Socket Layer Virtual Private Network), this paper presents the framework of SSL VPN which comprises two key techniques: virtual service and VPN stream hased access control model. By the virtual services created dynamically at the client server, SSL VPN can help traditional applications securely and transparently access VPN internal servers ; in view of VPN stream, it also tightly couples access control with VPN tunnel and transmission mechanism to implement the fine-grained access control and the intrusion detection of the application layer. We finally provided an implemented prototype and its related performance testing.
出处 《小型微型计算机系统》 CSCD 北大核心 2006年第2期228-232,共5页 Journal of Chinese Computer Systems
基金 国家自然科学基金项目(60373088)资助
关键词 SSL VPN 虚拟服务 访问控制 SSL VPN virtual services access control stream
  • 相关文献

参考文献10

  • 1Cohen R.On the establishment of an access VPN in broadband access networks[J].Communications Magazine,IEEE February 2003,41(2):156-163.
  • 2Kent S,Atkinson R.Security architecture for the internet protocol[S].RFC2401,November 1998.
  • 3Dierks T,Allen C.The TLS protocol version 1.0[S].RFC2246,January 1999.
  • 4Rescorla E,Schiffman A.The secure HyperText transfer protocol[S].RFC2660,August 1999.
  • 5Sandhu R S,Coyne E J,Feinstein H,Youman C.Role-based access control models[J].IEEE Computer,1996,29(2):38-47.
  • 6Dimitrakos T,Djordjevic I,Matthews B,et al.Policy-driven access control over a distributed firewall architecture[J].Policies for Distributed Systems and Networks,2002:228-231.
  • 7Jason J,Rafalow L,Vyncke E.IPSec configuration policy information model[S].RFC3585,August 2003.
  • 8Xin Guo,Kun Yang,Galis A,et al.A Policy-based network management system for IP VPN[C].Communication Technology Proceedings,2003.ICCT 2003.2003,(2):1630-1633.
  • 9Ryutov T,Neuman C,Dongho Kim.Integrated access control and intrusion detection for Web servers[J].Parallel and Distributed Systems,IEEE Transactions.September 2003,(14):841-850.
  • 10Bhatt D V,Schulze S,et al.Secure internet access to gateway using secure socket layer[J].Virtual Environments.Human-Computer Interfaces and Measurement Systems.2003:157-162.

同被引文献57

引证文献15

二级引证文献60

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部