DocumentCode :
1679063
Title :
Dynamic Network Separation for IPv6 Network Security Enhancement
Author :
Suzuki, Satoshi ; Kondo, Satoshi
Author_Institution :
Hitachi, Ltd.
fYear :
2005
Firstpage :
22
Lastpage :
25
Abstract :
Currently on the Internet, a network site is often secured by a firewall, filtering bogus traffic from outside at the border of the network site. This ’Border Defence Model’, however, obstructs the deployment of IPv6 applications and services, because the firewall negates the benefits of IPv6, such as end-to-end communication and IPsec. To solve this problem, the ’Quarantine Model’ is proposed. In this model, network nodes are accommodated to separate network segments according to their security levels, and a different security policy is implemented on each network segment. This ’divide and conquer’ framework provides more flexible and better network security for the Quarantine Model. This paper discusses how to conduct dynamic network separation, which is mandatory to the Quarantine Model, and analyzes the pros and cons of separation methods.
Keywords :
Data security; IP networks; Laboratories; Level measurement; Network servers; Poles and towers; Protection; Protocols; TCPIP; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Applications and the Internet Workshops, 2005. Saint Workshops 2005. The 2005 Symposium on
Print_ISBN :
0-7695-2263-7
Type :
conf
DOI :
10.1109/SAINTW.2005.1619969
Filename :
1619969
Link To Document :
بازگشت