节点文献
基于有向图的网络安全策略冲突研究
Network Security Policy Conflic Research Based on Directed-Graph
【作者】 胡义香;
【导师】 李先义;
【作者基本信息】 南华大学 , 计算机应用技术, 2007, 硕士
【摘要】 在IETF、DMTF等国际组织和IBM、CISCO等众多厂商的大力支持下,基于策略的管理逐渐被广泛应用在网络管理、安全管理等领域,并成为新一代分布式系统管理的一大特色。保证安全策略的协同工作和一致性是实现分布式系统安全管理需要首先解决的问题。因此,对安全策略的表示、分类和对策略之间冲突的检测和消解是实现统一的安全管理的首要目标,也是基于策略的网络安全应用中的难点之一。本文对已有的两种典型的策略处理框架进行了介绍,在总结这两种安全策略处理框架优缺点的基础上提出一种可适应的安全策略框架。在此安全策略框架中,针对现有网络安全策略冲突分类不完善,对基于过滤的网络安全策略中的冲突进行全面分类并给予形式化的描述,提供了一种全面的冲突分析框架。同时针对现有安全策略冲突检测方法的不足,对已有典型的冲突检测方法进行了深入分析,比较了它们处理过程中存在的优势和局限性,在此基础上提出了基于有向图的安全策略冲突检测模型,结合在实践中经常用到的几种策略执行优先权方案,进一步提出了策略冲突自动检测与恢复模型。最后,本文设计并进行了一个基于有向图的安全策略冲突检测仿真实验,仿真验证本文提出方法的有效性,并对模型框架及算法进行了评估和检验。结果说明框架具有可适应性,算法具有很高的冲突识别率,并具有合理的时空复杂度,具有一定的实用价值。
【Abstract】 Supported by the international organization of IETF and DMTF, and the manufacturer of IBM and CISCO, etc, Policy-based management is gradually applied in the fields of network management, security management and so on, and becomes a characteristic of the new distributed system management. To ensure security policies to work consistently and to maintain its own consistency is the first thing of realizing distributed system management to be resolved. Thus, the description and classification of security policy and the detection and solution of the security policy conflicts are the chief goal of achieving uniform security management, and also one of the most difficult problems in the field of the security management.The paper introduces two typical security policy frameworks in existence. Based on their virtues and flaws, then presents an adaptable security policy framework. In this security policy framework, in view of the faultiness of policy conflicts classification, the paper presents a comprehensive classification of the conflicts in filtering-based network security policy, gives its formal description and offers a comprehensive conflict analysis framework. In view of the shortcoming of previous security policy conflict detection methods, the paper deeply analyzes these typical methods on the policy conflict detection, and gives each method’s advantages and limitation on every aspects. Based on this idea, the paper presents the directed-graph-based security policy conflict detection model. Combining with a few policy enforcement priority often used in practice, the paper presents an automatic detection and recovery model of policy conflict.Finally, the paper designs and accomplishes a simulation experiment of security policy conflict detection based on directed-graph to verify the validness of the method mentioned here and to evaluate the model framework and arithmetics. The results show that the framework is adaptable and the arithmetics, which have high conflict identification ratio and reasonable space and time complex degree, have the more practicality value.
【Key words】 Network Security; Security Management; SecurityPolicy; Policy Conflict; Conflict detection;
- 【网络出版投稿人】 南华大学 【网络出版年期】2008年 01期
- 【分类号】TP393.08
- 【被引频次】3
- 【下载频次】294