XML Based Adaptive IPSEC Policy Management in a Trust Management Context

Abstract

TCP/IP provided the impetus for the growth of the Internet and the IPsec protocol now promises to add to it the desired security strength IPsec provides users with a mechanism to enforce a range of security services for both confidentiality and integrity, enabling them to securely pass information across networks, Dynamic parameterization of IPsec further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions, The IPsec implementation in OpenESD works in conjunction with the Trust Management System, KeyNote, to achieve this, However the KeyNote engine requires that an IPsec policy be defined in the KeyNote specification syntax, Defining a security policy in the KeyNote Specification language is, however, extremely difficult and the complexity of the language could lead to incorrect specification of the desired policy, thus degrading the security of the network, This thesis looks into an alternative XML representation of this language and a graphical user interface to evolve a consistent and correct security policy, The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques for correctness verification and validation.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Sep 01, 2002
Accession Number
ADA407100

Entities

People

  • Raj Mohan

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Computer Communications
  • Computer Network Security
  • Computer Networks
  • Computer Programming
  • Computer Science
  • Cryptography
  • Cybersecurity
  • Electronic Mail
  • Graphical User Interface
  • Information Systems
  • Language
  • Network Protocols
  • Network Science
  • Programming Languages
  • Security Protocols
  • Transport Protocols
  • User Interface

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Database Systems and Applications
  • Systems Analysis and Design