Title :
Security management for large computer networks
Author :
Duan, Haixin ; Wu, Jianping
Author_Institution :
Network Res. Center, Tsinghua Univ., Beijing, China
Abstract :
Security management is one of the five management functions defined by ISO/OSI, which covers two aspects: security of management and management of security. As to management of network security, we give security management requirements for large computer networks, combined with our management experience of managing CERNET. From our experience, the widely used firewalls in the Internet are lacking in the capability to be remotely managed on a large scale, especially multi-vendor network environment. Addressing these problems, the concept of high level security policy management is proposed for large networks. To support high level policy management and collaborative management of multi-vendor firewalls, a definition for a common firewall MIB (CFWMIB) and a common format for the TRAP events record are proposed. For the aspect of security of network management, we present a security architecture which is implemented in our web-based network management system. Flexible authentication and role-based access control mechanisms of the architecture are described. Our ongoing and future research is also outlined.
Keywords :
computer network management; telecommunication security; CERNET; CFWMIB; TRAP events record; authentication; common firewall MIB; firewalls; format; high level security policy management; large computer networks; management functions; management of security; multi-vendor firewall; multi-vendor network environment; network security; role-based access control mechanisms; security management; security of management; web-based network management system; Access control; Authentication; Collaboration; Computer network management; Computer security; Environmental management; IP networks; ISO; Large-scale systems; Open systems;
Conference_Titel :
Communications, 1999. APCC/OECC '99. Fifth Asia-Pacific Conference on ... and Fourth Optoelectronics and Communications Conference
Conference_Location :
Beijing, China
Print_ISBN :
7-5635-0402-8
DOI :
10.1109/APCC.1999.820481