DocumentCode :
1653093
Title :
Domain based Internet security policy management
Author :
Zao, John ; Sanchez, Luis ; Condell, Matthew ; Lynn, Charles ; Fredette, Matthew ; Helinek, Pamela ; Krishnan, Pajesh ; Jackson, Alden ; Mankins, David ; Shepard, Marla ; Kent, Stephen
Author_Institution :
BBN Technol. Inc., Cambridge, MA, USA
Volume :
1
fYear :
2000
fDate :
6/22/1905 12:00:00 AM
Firstpage :
41
Abstract :
As security devices and protocols become widely used on the Internet, the task of managing and processing communication security policies grows steeply in its complexity. This paper presents a scaleable, robust, secure distributed system that can manage communication security policies associated with multiple network domains and resolving the policies-esp. those that specify the use of IP-AH/ESP security protocols-into security requirements for inter-domain communication. Technology innovation includes a formal model for IPsec policy specification and resolution, a platform independent policy specification language and a distributed policy server system. The formal model consists of a hierarchical domain model for IPsec policy enforcement and a lattice model of IPsec policy semantics. The policy specification language enables users to specify IPsec policies using the formal model regardless of the make of the security devices. The policy servers maintain the security policies in a distributed database, and negotiate the security associations for protecting inter-domain communication. Both the policy database and the policy exchange protocol are protected from passive and active attacks. Several UNIX implementations are available for non-commercial uses
Keywords :
Internet; computational complexity; network servers; protocols; IP-AH/ESP security protocols; IPsec policy specification; communication security policies; distributed database; domain based Internet security policy management; formal model; hierarchical domain model; inter-domain communication; multiple network domains; policy exchange protocol; policy specification language; protocols; secure distributed system; security requirements; Communication system security; Communications technology; Data security; Electrostatic precipitators; Internet; Protection; Protocols; Robustness; Specification languages; Technological innovation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
DARPA Information Survivability Conference and Exposition, 2000. DISCEX '00. Proceedings
Conference_Location :
Hilton Head, SC
Print_ISBN :
0-7695-0490-6
Type :
conf
DOI :
10.1109/DISCEX.2000.824955
Filename :
824955
Link To Document :
بازگشت