Title :
CLID: A general approach to validate security policies in a dynamic network
Author :
Yang, Yanyan ; Martel, Charles U. ; Wu, S. Felix
Author_Institution :
Dept. of Comput. Sci., Univ. of California, Davis, CA
fDate :
May 21 2007-Yearly 25 2007
Abstract :
Many researchers have considered security policy management, including how to configure policies manually and even how to automatically generate security policies based on security requirements. Both can be error prone, especially when properties of the network topology change, because security requirements are usually not bound to any particular route path. Our DETER lab emulation results show that conflicts could be caused by these factors. Therefore, a systematic way to validate the correctness of the security policies is essential. This paper presents an approach, CLID (conflict and looping identification and detection), to verify whether a set of security policies (e.g. IPSec/VPN tunnels) satisfy the given security requirements, without causing any conflicts. This approach utilizes the definition of a security policy lo include network routing data as well as traffic selector information, thus it works for general network topologies. We also analyze and justify the correctness of the approach. The paper concludes with our simulation results and addresses future work.
Keywords :
IP networks; protocols; telecommunication network management; telecommunication network routing; telecommunication network topology; telecommunication security; telecommunication traffic; virtual private networks; CLID; IP layer security protocol; IPSec/VPN tunnel; dynamic network security policy; end-to-end traffic flow; network routing path; network security policy management; network topology; Authentication; Computer security; Cryptography; Data security; Information security; Interference; Network topology; Routing; Telecommunication traffic; Virtual private networks;
Conference_Titel :
Integrated Network Management, 2007. IM '07. 10th IFIP/IEEE International Symposium on
Conference_Location :
Munich
Print_ISBN :
1-4244-0798-2
Electronic_ISBN :
1-4244-0799-0
DOI :
10.1109/INM.2007.374764