期刊文献+

IPSec网关的一种分布式配置方法 被引量:1

Distributed configuring method for IPSec gateways
下载PDF
导出
摘要 IPSec协议的一种应用模式是采用IPSec网关间隔各个网络段,通过网关的策略配置,实现安全通信需求。然而,交叉的IPSec策略可能导致信息回流,引发策略冲突,破坏安全需求。提出IPSec网关的一种基于多agent系统的配置方法,自动分布式生成无冲突的IPSec策略集,可以避免集中式生成方法单点失效的弱点。模拟实验验证了这种方法的可行性。 An application scenario for IPSec is to partition a network by IPSec gateways. The security requirements are implemented by IPSec policies between gateways. However, the overlapping tunnels may lead to network traffic looping and introduce policy conflicts. A distributed method is proposed, named DistlPSec,to generate conflict free policies for IPSec gateways. The simulated experiments show the validity of the proposed method.
作者 唐屹 张连宽
出处 《计算机工程与应用》 CSCD 北大核心 2008年第14期127-129,141,共4页 Computer Engineering and Applications
基金 广东省科技公关计划(the Key Technologies R&D Program of Guangdong Province,China under Grant No.2005B10101024) 广东省信息安全技术重点实验室开放基金
关键词 IPSec配置 分布式 策略冲突与消解 IPSee configuration distribution policy eonflietion and resolution
  • 相关文献

参考文献5

  • 1Fu Z, Wu S, Huang H, et al. IPsec/VPN security policy [ C ]//IEEE Policy 2001 Workshop on Correctness, Conflict Detection and Resolution ,2001:39-56.
  • 2Yang Y, Martel C, Wu S. On building the minimal number of tunnelsan ordered-split approach to manage IPSec/VPN policies [ C ]//Proceedings of NOMS' 04,2004,1:277-290.
  • 3Chang C, Chiu Y, Lei C. Automatic generation to conflict-free IPSec policies [ C ]//Proceedings of FTNDS' 05,2005:233-246.
  • 4Chen K, Liu Y, Liu T, et al. ZERO-Conflict: a grouping-based approach for automatic generation of IPSec/VPN security policies [ C]//LNCS 4269 :Proceedings of DSOM' 06,2006 : 197-208.
  • 5Liu J,Jing H,Tang Y. Multi-agent oriented constraint satisfaction [ J ]. Artificial Intellgence ,2002,136 ( 1 ) : 101-144.

同被引文献5

  • 1Fu Z,Wu S,Huang H,et al.IPsec/VPN security policy: correctness,conflict detection and resolution[C]//IEEE Policy 2001 Workshop, 2001 : 39-56.
  • 2Yang Y,Martel C,Wu S.On building the minimal number of tunnels-an ordered-split approach to manage IPSec/VPN policies[C]// Proceedings of NOMS'04,2004:277-290.
  • 3Chang C,Chiu Y,Lei C.Automatic generation to conflict-free IPSec policies[C]//Proceedings of FTNDS'05,2005:233-246.
  • 4Liu J,Jing H,Tang Y.Multi-agent oriented constraint satisfaction[J]. Artificial Intelligence, 2002,136( 1 ) : 101-144.
  • 5Hirayama K,Yokoo M.The distributed breakout algorithm[J].Artificial Intelligence,2005,161 (1/2):89-116.

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部