首页> 外文会议> >Application of virtual private networking technology to standards-based management protocols across heterogeneous firewall-protected networks
【24h】

Application of virtual private networking technology to standards-based management protocols across heterogeneous firewall-protected networks

机译:虚拟专用网络技术在跨受防火墙保护的网络中基于标准的管理协议中的应用

获取原文

摘要

There has been tremendous growth within DoD of enterprise-wide COTS-based messaging and communications systems, including the Defense Message System, the Global Command and Control System, and the Global Combat Support System. To economize on development costs, standards-based protocols-including SMTP, SNMP, FTP, Telnet, and HTTP-are used to implement the underlying functionality of these systems, including messaging and service management. Vulnerabilities in such standards-based protocols have been identified, and security over the Internet and its connected systems has become an ever-increasing concern. Network security policies have been created to address the dilemma of protecting local systems from external attack while permitting easy communications between authorized parties. A burgeoning industry of firewall manufacturers has arisen to meet the challenge of implementing these policies effectively, safely, and reliably. Virtual private networking (VPN) technology was developed to enable separate firewall-protected enclaves to safely exchange data over unsecured networks. This technology is still maturing and standardized-using IPSec, ISAKMP, and DES encryption-to enable separate VPN implementations to interoperate over shared networks. This paper studies how virtual private networking technology can be employed to protect the use of standards-based service management protocols-including FTP, Telnet, SNMP, and NTP-across heterogeneous firewall-protected networks, balancing the requirements of enterprise service management with the need for local-level network security.
机译:国防部内部的企业级基于COTS的消息传递和通信系统有了巨大的发展,包括国防消息系统,全球指挥与控制系统和全球战斗支持系统。为了节省开发成本,使用了基于标准的协议(包括SMTP,SNMP,FTP,Telnet和HTTP)来实现这些系统的基础功能,包括消息传递和服务管理。已经发现了这种基于标准的协议中的漏洞,并且Internet及其连接的系统上的安全性越来越引起人们的关注。已经创建了网络安全策略来解决保护本地系统免受外部攻击的难题,同时允许授权方之间的轻松通信。新兴的防火墙制造商行业已经出现,以应对有效,安全和可靠地实施这些策略的挑战。开发了虚拟专用网络(VPN)技术,以使受防火墙保护的独立区域能够在不安全的网络上安全地交换数据。这项技术仍在日趋成熟和标准化(使用IPSec,ISAKMP和DES加密),以使单独的VPN实现能够在共享网络上互操作。本文研究了如何在跨异构防火墙保护的网络中使用虚拟专用网络技术来保护基于标准的服务管理协议(包括FTP,Telnet,SNMP和NTP)的使用,从而平衡企业服务管理的需求与需求用于本地级别的网络安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号