VPNs White Papers

IPsec/VPN Security Policy Engineering: Automatic Generation and Conflict Detection

Overview IPsec is a useful IP layer security protocol which can provide authentication and encryption for end-to-end traffic flow, but configuring IPsec VPN tunnels is notoriously complicated because it has so many options (key exchange, ciphers, authentication etc) to configure. Thus the ultimate solutions to the security requirements are often prone to errors, let alone that dynamic routing changes can also cause troubles when interacting with existing IPsec tunnels. One minor configuration mistake or one subtle change (e.g. in routing) can cause insecure message transmission or even packet looping. Therefore, in this dissertation, it first proposes a network framework, BANDS, to provide an infrastructure where each domain has a requirement server to correctly handle inter-domain security requirements and policies.

Further White Paper Details
PublisherUniversity of California File FormatPDF
Date PublishedJune 2006
FormatWhite Papers   
Topics

Quick Sitemap Links: