首页> 外文学位 >Enabling the intelligent network services in the presence of the end -to -end security model of Windows XP IPSec protocols.
【24h】

Enabling the intelligent network services in the presence of the end -to -end security model of Windows XP IPSec protocols.

机译:在存在Windows XP IPSec协议的端到端安全模型的情况下启用智能网络服务。

获取原文
获取原文并翻译 | 示例

摘要

The most widely used network security strategy today, concentrates on preventing attacks from outsiders. While this is true, it ignores major attacks that might be initiated from insiders within corporate LANs. Under Windows XP/2000/2003 networks, most LAN traffic is not secured. Therefore, malicious employees, visitors, or partners might plug in sniffing devices to monitor and analyze traffic. Security countermeasures such as firewalls at the perimeter cannot prevent such attacks. Consequently, there is a high demand to adopt an end-to-end security model that ensures secure communications between any two Windows XP/2000/2003 machines. The transport mode of Windows XP IPSec protocols provides such a model. Unfortunately, this security model disables a wide range of Intelligent Network Services (INS Services) that are inevitable for operating Windows-based LANs, such as internal firewalls, Network Intrusion and Prevention Systems (NIDS and NIPS), Network Address Translation (NAT), Network Monitoring tools, and Traffic Classification, Prioritization, and Port Management services. This dissertation investigates this critical issue and provides a classification model of INS Services that precisely defines the access requirements of a wide list of INS Services. This classification model aims to provide an insight into the conflict that exists between Windows XP/2000 IPSec protocols and INS Services. To resolve this conflict, two models are presented. The first is the IP Option Field Model (IPOFM Model), a flexible and easy to implement solution that allows a wide subset of INS Services to co-exist with the transport mode of Windows 2000 IPSec protocols. It does not change the IPSec packet format or the Security Association (SA) mechanism. It does, however, need a change of processing at the source and destination Windows XP machines as well as an intermediate host that implements an INS Service. The second model is a Two Layer Protection Model (TLPM Model) which is also flexible and provides a granular solution that enables all types of INS Services to function within restrictions of the end-to-end security model of Windows 2000 IPSec Protocols in Windows Networks. It introduces changes to the IPSec packet format, SA mechanism, and processing at the source and destination Windows XP machines as well as an intermediate host that implements an INS Service. The model also introduces processing overhead, as it might need to run two different authentication and/or encryption algorithms.;Using Windows XP IPSec protocols affect several performance parameters such as scalability, latency, and throughput. Encryption algorithms play a major factor in degrading throughput of Windows XP networks. The default values of TCP parameters are not suitable for Windows XP networks that utilize Giga Ethernet technology. Tuning these parameters, mainly TCP windows size, is needed to improve the performance of Windows XP IPSec protocols. This dissertation addresses these issues and provides a quantitative analysis of Windows XP/2000/2003 IPSec protocols.
机译:当今使用最广泛的网络安全策略集中在防止外部人的攻击上。尽管这是事实,但它忽略了可能由公司LAN内部人员发起的重大攻击。在Windows XP / 2000/2003网络中,大多数LAN流量不受保护。因此,恶意员工,访客或合作伙伴可能会插入嗅探设备来监视和分析流量。诸如防火墙之类的安全对策无法阻止此类攻击。因此,迫切需要采用端到端安全模型来确保任何两台Windows XP / 2000/2003计算机之间的安全通信。 Windows XP IPSec协议的传输模式提供了这样的模型。不幸的是,此安全模型禁用了运行基于Windows的LAN不可避免的各种智能网络服务(INS服务),例如内部防火墙,网络入侵和防御系统(NIDS和NIPS),网络地址转换(NAT),网络监视工具以及流量分类,优先级和端口管理服务。本文研究了这个关键问题,并提供了INS Services的分类模型,该模型精确地定义了许多INS Services的访问要求。此分类模型旨在深入了解Windows XP / 2000 IPSec协议与INS Services之间存在的冲突。为了解决该冲突,提出了两种模型。第一个是IP选项字段模型(IPOFM模型),它是一种灵活且易于实现的解决方案,它允许INS服务的广泛子集与Windows 2000 IPSec协议的传输模式共存。它不会更改IPSec数据包格式或安全关联(SA)机制。但是,它确实需要更改源Windows XP和目标Windows XP计算机以及实现INS服务的中间主机的处理。第二种模型是两层保护模型(TLPM模型),该模型也很灵活,并且提供了一种精细的解决方案,使所有类型的INS服务都可以在Windows网络中Windows 2000 IPSec协议的端到端安全模型的限制内运行。 。它引入了对IPSec数据包格式,SA机制以及源Windows XP和目标Windows XP计算机以及实现INS服务的中间主机的处理的更改。由于可能需要运行两种不同的身份验证和/或加密算法,该模型还引入了处理开销。使用Windows XP IPSec协议会影响多个性能参数,例如可伸缩性,延迟和吞吐量。加密算法是降低Windows XP网络吞吐量的主要因素。 TCP参数的默认值不适用于使用Giga以太网技术的Windows XP网络。需要调整这些参数(主要是TCP窗口大小)以提高Windows XP IPSec协议的性能。本文解决了这些问题,并对Windows XP / 2000/2003 IPSec协议进行了定量分析。

著录项

  • 作者

    ALmeshary, Nasser Zaid.;

  • 作者单位

    Florida Institute of Technology.;

  • 授予单位 Florida Institute of Technology.;
  • 学科 Engineering Electronics and Electrical.;Computer Science.
  • 学位 Ph.D.
  • 年度 2004
  • 页码 224 p.
  • 总页数 224
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 农学(农艺学);
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号