XML based adaptive IPsec policy management in a trust management context

Approved for public release, distribution is unlimited === TCP/IP provided the impetus for the growth of the Internet and the IPsec protocol now promises to add to it the desired security strength. IPsec provides users with a mechanism to enforce a range of security services for both confidentiality...

Full description

Bibliographic Details
Main Author: Mohan, Raj.
Other Authors: Irvine, Cynthia E.
Published: Monterey, California. Naval Postgraduate School 2012
Online Access:http://hdl.handle.net/10945/4824
id ndltd-nps.edu-oai-calhoun.nps.edu-10945-4824
record_format oai_dc
spelling ndltd-nps.edu-oai-calhoun.nps.edu-10945-48242015-02-07T04:05:41Z XML based adaptive IPsec policy management in a trust management context Mohan, Raj. Irvine, Cynthia E. Levin, Timothy E. Naval Postgraduate School Computer Science Information Technology Management Approved for public release, distribution is unlimited TCP/IP provided the impetus for the growth of the Internet and the IPsec protocol now promises to add to it the desired security strength. IPsec provides users with a mechanism to enforce a range of security services for both confidentiality and integrity, enabling them to securely pass information across networks. Dynamic parameterization of IPsec further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. The IPsec implementation in OpenBSD works in conjunction with the Trust Management System, KeyNote, to achieve this. However the KeyNote engine requires that an IPsec policy be defined in the KeyNote specification syntax. Defining a security policy in the KeyNote Specification language is, however, extremely difficult and the complexity of the language could lead to incorrect specification of the desired policy, thus degrading the security of the network. This thesis looks into an alternative XML representation of this language and a graphical user interface to evolve a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques for correctness verification and validation. 2012-03-14T17:43:16Z 2012-03-14T17:43:16Z 2003-12 Thesis http://hdl.handle.net/10945/4824 Copyright is reserved by the copyright owner Monterey, California. Naval Postgraduate School
collection NDLTD
sources NDLTD
description Approved for public release, distribution is unlimited === TCP/IP provided the impetus for the growth of the Internet and the IPsec protocol now promises to add to it the desired security strength. IPsec provides users with a mechanism to enforce a range of security services for both confidentiality and integrity, enabling them to securely pass information across networks. Dynamic parameterization of IPsec further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. The IPsec implementation in OpenBSD works in conjunction with the Trust Management System, KeyNote, to achieve this. However the KeyNote engine requires that an IPsec policy be defined in the KeyNote specification syntax. Defining a security policy in the KeyNote Specification language is, however, extremely difficult and the complexity of the language could lead to incorrect specification of the desired policy, thus degrading the security of the network. This thesis looks into an alternative XML representation of this language and a graphical user interface to evolve a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques for correctness verification and validation.
author2 Irvine, Cynthia E.
author_facet Irvine, Cynthia E.
Mohan, Raj.
author Mohan, Raj.
spellingShingle Mohan, Raj.
XML based adaptive IPsec policy management in a trust management context
author_sort Mohan, Raj.
title XML based adaptive IPsec policy management in a trust management context
title_short XML based adaptive IPsec policy management in a trust management context
title_full XML based adaptive IPsec policy management in a trust management context
title_fullStr XML based adaptive IPsec policy management in a trust management context
title_full_unstemmed XML based adaptive IPsec policy management in a trust management context
title_sort xml based adaptive ipsec policy management in a trust management context
publisher Monterey, California. Naval Postgraduate School
publishDate 2012
url http://hdl.handle.net/10945/4824
work_keys_str_mv AT mohanraj xmlbasedadaptiveipsecpolicymanagementinatrustmanagementcontext
_version_ 1716730489839026176