IPSec/VPN Security Policy: Correctness, Conflict Detection, and Resolution
Author(s) -
Zhi Fu,
S. Felix Wu,
He Huang,
Kung Loh,
Fengmin Gong,
Ilya Baldin,
Chong Xu
Publication year - 2001
Publication title -
lecture notes in computer science
Language(s) - English
Resource type - Book series
eISSN - 1611-3349
pISSN - 0302-9743
ISBN - 3-540-41610-2
DOI - 10.1007/3-540-44569-2_3
Subject(s) - ipsec , computer science , security policy , computer security , security association , correctness , domain (mathematical analysis) , network security policy , authentication (law) , security service , the internet , information security , security information and event management , cloud computing security , operating system , cloud computing , mathematical analysis , mathematics , programming language
IPSec (Internet Security Protocol Suite) functions will be executed correctly only if its policies are correctly specified and configured. Manual IPSec policy configuration is inefficient and error-prone. An erroneous policy could lead to communication blockade or serious security breach. In addition, even if policies are specified correctly in each domain, the diversified regional security policy enforcement can create significant problems for end-to-end communication because of interaction among policies in different domains. A policy management system is, therefore, demanded to systematically manage and verify various IPSec policies in order to ensure an end-to-end security service. This paper contributes to the development of an IPSec policy management system in two aspects. First, we defined a high-level security requirement, which not only is an essential component to automate the policy specification process of transforming from security requirements to specific IPSec policies but also can be used as criteria to detect conflicts among IPSec policies, i.e. policies are correct only if they satisfy all requirements. Second, we developed mechanisms to detect and resolve conflicts among IPSec policies in both intradomain and inter-domain environment.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom