...
首页> 外文期刊>International journal of internet protocol technology >A data flow-oriented specification method for analysing network security configurations
【24h】

A data flow-oriented specification method for analysing network security configurations

机译:一种面向数据流的规范化方法,用于分析网络安全配置

获取原文
获取原文并翻译 | 示例
           

摘要

The implementation of a network security policy requires the configuration of heterogeneous and complex security mechanisms (IPsec gateways, ACLs on routers, statefull firewalls, proxies, etc.). The complexity of this task resides in the number, the nature, and the interdependence of these mechanisms. Although several researchers have proposed different analysis tools, achieving this task requires experienced and proficient security administrators who can handle all these parameters. A generic formal theory that allows to reason about network data flows and security mechanisms is missing. In previous articles, we have proposed a formal data-flow-oriented model to detect network security conflicts. In this article, we supplement it with a generic model of equipment configuration constructed on our attribute-based approach. Network security services will be represented by specific atomic abstract functions called 'basic commands' that can modify the data flow. Based on this representation, we define an abstract model of configuration. Therefore, we specify our approach in coloured Petri networks to automate the conflicts detection analysis and test it on NAPT/IPsec scenario.
机译:网络安全策略的实施需要配置异构和复杂的安全机制(IPsec网关,路由器上的ACL,全状态防火墙,代理等)。这项任务的复杂性在于这些机制的数量,性质和相互依赖性。尽管一些研究人员提出了不同的分析工具,但是要实现此任务,需要经验丰富且精通的安全管理员,他们可以处理所有这些参数。缺少可以推理网络数据流和安全机制的通用形式理论。在先前的文章中,我们提出了一种面向数据流的正式模型来检测网络安全冲突。在本文中,我们通过基于属性的方法构建的通用设备配置模型对其进行补充。网络安全服务将由称为“基本命令”的特定原子抽象功能表示,这些功能可以修改数据流。基于这种表示,我们定义了一个抽象的配置模型。因此,我们在有色陪替氏网络中指定了我们的方法来自动进行冲突检测分析,并在NAPT / IPsec场景下对其进行测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号