• DocumentCode
    3214736
  • Title

    MLCC: A Multi Layered Correlative Control Mechanism for the VPN Topology

  • Author

    Ouyang, Kai ; Chu, Xiaowen ; Dong, Lijun ; Wang, Hengqing ; Cai, Ting

  • Author_Institution
    Sch. of Comput. Sci., Wuhan Univ. of Sci. & Tech., Wuhan
  • fYear
    2007
  • fDate
    29-31 July 2007
  • Firstpage
    37
  • Lastpage
    43
  • Abstract
    The security model is the key component in the security of network topology research. Especially in the virtual private network (VPN) topology, with the emergence of the tunneling, private routing and cipher technology in VPN, there are two embarrassments for the protection of the entire VPN topology. One is that internal services will be uncovered in the Internet by the tunneling, which can be compromised by attacking the client-side endpoint of a VPN tunnel. The other is that firewall and intrusion detection system (IDS) could not completely analyze the network packet content because of the private routing and cipher technology. Based on the analysis of the VPN topology, we put forward the multi-layered correlative control (MLCC) mechanism. MLCC is a multi-layered security protection mechanism based on VPN gateway incorporating client end-point, firewall, IDS and internal services. There are three types of correlative technology introduced in MLCC, which are endpoint extending, component correlation and service engine. By their combination, MLCC can turn the VPN protection into a correlative and full model and improve the security of the VPN topology. Finally, the performance analysis based on our prototype is presented.
  • Keywords
    telecommunication network topology; telecommunication security; virtual private networks; Internet; cipher technology; firewall; intrusion detection system; multi layered correlative control mechanism; network topology research security; private routing; virtual private network; Intrusion detection; Network topology; Performance analysis; Protection; Routing; Search engines; Security; Tunneling; Virtual private networks; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking, Architecture, and Storage, 2007. NAS 2007. International Conference on
  • Conference_Location
    Guilin
  • Print_ISBN
    0-7695-2927-5
  • Type

    conf

  • DOI
    10.1109/NAS.2007.39
  • Filename
    4286406