摘要
IPSec协议的一种应用模式是采用IPSec网关间隔各个网络段,通过网关的策略配置,实现安全通信需求。然而,交叉的IPSec策略可能导致信息回流,引发策略冲突,破坏安全需求。提出IPSec网关的一种基于多agent系统的配置方法,自动分布式生成无冲突的IPSec策略集,可以避免集中式生成方法单点失效的弱点。模拟实验验证了这种方法的可行性。
An application scenario for IPSec is to partition a network by IPSec gateways. The security requirements are implemented by IPSec policies between gateways. However, the overlapping tunnels may lead to network traffic looping and introduce policy conflicts. A distributed method is proposed, named DistlPSec,to generate conflict free policies for IPSec gateways. The simulated experiments show the validity of the proposed method.
出处
《计算机工程与应用》
CSCD
北大核心
2008年第14期127-129,141,共4页
Computer Engineering and Applications
基金
广东省科技公关计划(the Key Technologies R&D Program of Guangdong Province,China under Grant No.2005B10101024)
广东省信息安全技术重点实验室开放基金
关键词
IPSec配置
分布式
策略冲突与消解
IPSee configuration
distribution
policy eonflietion and resolution