Title :
An editor for adaptive XML-based policy management of IPsec
Author :
Mohan, Raj ; Levin, Timothy E. ; Irvine, Cynthia E.
Abstract :
The IPsec protocol provides a mechanism to enforce a range of security services for both confidentiality and integrity, enabling secure transmission of information across networks. Dynamic parameterization of IPsec, via the KeyNote trust management system, further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. However KeyNote requires that an IPsec policy be defined in the KeyNote specification syntax. Defining such a dynamic security policy in the KeyNote policy specification language is complicated and can lead to incorrect specification of the desired policy, thus degrading the security of the network. We present an alternative XML representation of this language and a graphical user interface to create and manage a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques to support administrative policy verification.
Keywords :
XML; data integrity; formal specification; formal verification; graphical user interfaces; security of data; specification languages; telecommunication security; transport protocols; IPsec protocol; KeyNote trust management system; XML representation; data integrity; graphical user interface; menu-driven editor; policy specification language; policy verification; security policy; Communication system security; Computer networks; Computer security; Data security; Degradation; Information security; Internet; Protocols; Specification languages; XML;
Conference_Titel :
Computer Security Applications Conference, 2003. Proceedings. 19th Annual
Print_ISBN :
0-7695-2041-3
DOI :
10.1109/CSAC.2003.1254332