首页> 外文期刊>International Journal of Information Security >Rigorous automated network security management
【24h】

Rigorous automated network security management

机译:严格的自动化网络安全管理

获取原文
获取原文并翻译 | 示例
           

摘要

Achieving a security goal in a networked system requires the cooperation of a variety of devices, each device potentially requiring a different configuration. Many information security problems may be solved with appropriate models of these devices and their interactions, giving a systematic way to handle the complexity of real situations. We present an approach, rigorous automated network security management, that front-loads formal modeling and analysis before problem solving, thereby providing easy-to-run tools with rigorously justified results. With this approach, we model the network and a class of practically important security goals. The models derived suggest algorithms that, given system configuration information, determine the security goals satisfied by the system. The modeling provides rigorous justification for the algorithms, which may then be implemented as ordinary computer programs requiring no formal methods training to operate. We have applied this approach to several problems. In this paper we describe two: distributed packet filtering and the use of IP security (IPsec) gateways. We also describe how to piece together the two separate solutions to these problems, jointly enforcing packet filtering as well as IPsec authentication and confidentiality on a single network.
机译:在网络系统中实现安全目标需要多种设备的协作,每个设备可能需要不同的配置。可以使用这些设备的适当模型及其交互来解决许多信息安全问题,从而提供一种系统的方式来处理实际情况的复杂性。我们提出了一种严格的自动化网络安全管理方法,该方法可以在解决问题之前预先加载正式的建模和分析,从而提供易于操作且具有严格合理结果的工具。使用这种方法,我们可以对网络和一类实际上很重要的安全目标进行建模。推导的模型提出了算法,这些算法在给定系统配置信息的情况下确定系统满足的安全目标。该建模为算法提供了严格的依据,然后可以将其实现为不需要任何正式方法培训即可操作的普通计算机程序。我们已经将此方法应用于一些问题。在本文中,我们描述了两个:分布式数据包过滤和IP安全(IPsec)网关的使用。我们还将描述如何将针对这些问题的两个单独的解决方案组合在一起,共同在单个网络上共同实施数据包筛选以及IPsec身份验证和机密性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号