期刊文献+

面向应用的IPSec系统策略管理机制 被引量:1

An Application-Oriented IPSec System Policy Management Mechanism
下载PDF
导出
摘要 针对现有IPSec系统策略机制的不足,本文提出了一种面向应用的IPSec系统策略管理机制,通过监视应用程序的socket活动,实时地设置好相应的IPSec策略,对IP流实施细粒度的、不同等级的保护;同时,提供高级语言形式的策略设置语句,以满足用户添加和修改细粒度IPSec策略的需要;提供解决策略冲突的算法,将相互冲突的需求转化为无冲突的策略。该机制可以提高现有IPSec系统的性能,使其更好地满足网络实际环境的需要。 In view of the flaws of the existing IPSec system policy mechanisms, this paper presents an application-oriented IPSec system policy management mechanism. By monitoring the socket activities of the application layer, we create the corresponding IPSec policy in a real-time manner, and provide different grades of fine-grained protection for the IP flow. We also present the expressions of policy setting that uses a high-level language form,in order to satisfy the users'needs to add, change and delete the fine-grained IPSec policy. In addition, we give an algorithm to resolve the policy conflicts, and transform the conflicting policies into conflict-free ones. The mechanism can improve the performance of the existing IPSec, so it can meet the actual network environment better.
出处 《计算机工程与科学》 CSCD 2007年第5期15-18,49,共5页 Computer Engineering & Science
关键词 IPSEC策略 策略冲突 socket监控 消除冲突 IPSec policy policy conflict socket monitoring conflict removal
  • 相关文献

参考文献10

  • 1Kent S,Atkinson R.Security Architecture for the Internet Protocol[S].RFC 2401,1998.
  • 2Arkko J,Nikander P.Limitations of IPsec Policy Mechanisms[A].Proc of the 11th Int'l Workshop on Security Protocols[C].2003.241-251.
  • 3Fu Z,Wu S F,Huang H.IPSec/VPN Security Policy:Correctness,Conflict Detection,and Resolution[A].IEEE Policy 2001[C].2001.39-56.
  • 4Fu Z,Wu S F.Automatic Generation of IPSec/VPN Security Policies in an Intra-Domain Environment[A].Proc of the 12th Int'l Workshop on Distributed System Operation and Management Workshop[C].2001.
  • 5Chang C L,Chiu Y P,Lei C L.Automatic Generation of Conflict-Free IPSec Policies[A].Proc of the Int'l Conf on Formal Techniques for Networked and Distributed Systems[C].2005.233-246.
  • 6Harkins D.The Internet Key Exchange(IKE)[S].RFC 2409,1998.
  • 7Maughan D,Schertler M,Schneider M.Internet Security Association and Key Management Protocol (ISAKMP)[S].RFC 2408,1998.
  • 8余胜生,周敬利,陈向荣.IPSec-VPN中应用PKI的研究与实现方案[J].计算机仿真,2003,20(3):45-48. 被引量:7
  • 9Yin Heng,Wang Haining.Building an Application Aware IPsec Policy System[A].Proc of the 14th USENIX Security Symp[C].2005.315-330.
  • 10Case J D,Fedor M,Schoffstall M L,et al.A Simple Network Management Protocol (SNMP)[S].RFC 1157,1990.

二级参考文献3

共引文献6

同被引文献4

引证文献1

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部