Proceedings Article10.1109/DISCEX.2000.824976
Celestial security management system
Chong Xu,Fengmin Gong,Ilia Baldine,C. Sargor,F. Jou,Shyhtsun Felix Wu,Zhi Fu,He Huang +7 more
- 25 Jan 2000
- Vol. 1, pp 162-172
TL;DR: A security management architecture that can automatically discover effective security policies and mechanisms along any network path, dynamically configure security mechanisms across protocol layers and across the network, and adaptively re-configure these mechanisms to maintain certain levels of security services when the network is under stress is developed.
read more
Abstract: There has been a vast amount of research and development effort aimed at providing solutions and products that address the security needs in the information age. Each solution tends to address only a particular facet of the security problem and only accessible to limited protocols or applications. Moreover, ad hoc deployment of some solutions (e.g., firewalls and IPsec) can hinder our ability to collaborate across networks. A very important question is how any application can discover policy restrictions brought about by these solutions/mechanisms, and make efficient use of them to satisfy the application's security goals. The Celestial project addresses this question by developing a security management architecture that can (1) automatically discover effective security policies and mechanisms along any network path, (2) dynamically configure security mechanisms across protocol layers and across the network, (3) adaptively re-configure these mechanisms to maintain certain levels of security services when the network is under stress. This paper describes the Celestial system design and implementation, and reports the current status of the project.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Ad hoc network routing and security: A review
TL;DR: The security attributes and goals of ad hoc network are considered, the latest developments of current routing and security mechanissm including encryption, protocols, user authentication, and physical security are reviewed, and the new approaches trying to solve current problems are explored.
49
Model-based configuration of VPNs
Ingo Lück,S. Vogel,Heiko Krumm +2 more
- 07 Aug 2002
TL;DR: This work applies the approach of model-based management where the system itself as well as the management objectives are represented by graphical object instance diagrams and a combination of tool and libraries supports their interactive construction and automated analysis.
25
Bands: an inter-domain Internet security policy management system for IPSec/VPN
Yanyan Yang,Z. Fu,Shyhtsun Felix Wu +2 more
- 24 Mar 2003
TL;DR: A distributed framework and protocol, BANDS, for inter-domain policy negotiation and generation based on decentralized and predefined security requirements for IPSec/VPN policies is presented.
A multi-domain security policy distribution architecture for dynamic IP based VPN management
Francois Barrere,Abdelmalek Benzekri,Frédéric Grasset,Romain Laborde +3 more
- 05 Jun 2002
TL;DR: This paper proposes an upgradeable architecture enabling policy distribution for multiple purposes of VPN technologies, and proposes a sound solution to the policy distribution issues between multiple independent administrative domains.
6
References
The TLS Protocol Version 1.0
T. Dierks,C. Allen +1 more
- 01 Jan 1999
TL;DR: This document specifies Version 1.0 of the Transport Layer Security (TLS) protocol, which provides communications privacy over the Internet by allowing client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.
2.2K
The Internet Key Exchange (IKE)
D. Harkins,D. Carrel +1 more
- 01 Nov 1998
TL;DR: ISAKMP ([MSST98]) provides a framework for authentication and key exchange but does not define them.
1.3K
The RC5 encryption algorithm
Ronald L. Rivest
- 14 Dec 1994
TL;DR: This document describes the RC5 encryption algorithm, a fast symmetric block cipher suitable for hardware or software implementations and a novel feature of RC5 is the heavy use of data-dependent rotations.
Internet Security Association and Key Management Protocol (ISAKMP)
D. Maughan,M. Schertler,M. Schneider,J. Turner +3 more
- 01 Nov 1998
TL;DR: A Security Association protocol that negotiates, establishes, modifies and deletes Security Associations and their attributes is required for an evolving Internet, where there will be numerous security mechanisms and several options for each security mechanism.
Internet Security Association and Key Management Protocol (ISAKMP) Status of this Memo
D. Maughan,M. Schertler,M. Schneider,J. Turner +3 more
- 01 Jan 1998
TL;DR: The Internet Security Association and Key Management Protocol (ISAKMP) as discussed by the authors is a key management protocol that allows the creation and management of security associations, key generation techniques, and threat mitigation (e.g. denial of service and replay attacks).
450
Related Papers (5)
Tony Kenyon
- 01 Jan 2002
Xianping Wu
- 01 Mar 2010
Kalyani Kadam,Sonia K. Gajre,R. L. Paikrao +2 more
- 03 Oct 2012