Title :
Bands: an inter-domain Internet security policy management system for IPSec/VPN
Author :
Yang, Yanyan ; Fu, Zhi ; Wu, S. Felix
Author_Institution :
Dept. of Comput. Sci., California Univ., Davis, CA, USA
Abstract :
IPSec/VPN is widely deployed for users to remotely access their corporate data. IPSec policies must be correctly set up for VPN to provide anticipated protection. Manual policy setup is unscalable, inefficient and error-prone. Automated policy generation to comply with and enforce high-level security policies is desired but difficult, especially in an inter-domain environment when a VPN traverses multiple domains. This paper presents a distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation. The BANDS architecture consists of two phases: AS (autonomous system) route path discovery and an inter-domain collaborative protocol for policy negotiation among the autonomous systems discovered in the first phase. Each AS conceptually has one security requirement server responsible for the task of inter-domain policy negotiation. Following this two-step process in BANDS, a set of distributed security policies (for the implementation of policy enforcement) is automatically negotiated/generated based on decentralized and predefined security requirements.
Keywords :
Internet; business communication; computer network management; protocols; telecommunication security; virtual private networks; AS route path discovery; BANDS; IPSec policies; VPN; automated policy generation; autonomous system; collaborative protocol; corporate data; decentralized security requirements; distributed security policies; high-level security policies; inter-domain policy negotiation; security requirement server; Communication system security; Computer network management; Data security; Home automation; Internet; Portable computers; Protection; Protocols; Telecommunication traffic; Virtual private networks;
Conference_Titel :
Integrated Network Management, 2003. IFIP/IEEE Eighth International Symposium on
Print_ISBN :
1-4020-7418-2
DOI :
10.1109/INM.2003.1194183