Abstract
IPSec has been popularly used in protecting data over IP network; however, how to detect and avoid policy conflicts is a big challenge. Under current architecture, user-space process can directly manipulate security associations database (SADB) or security policies database (SPDB) causing inter-application conflict, lack of access control, lack of conflict avoiding and recovering, and conflict diffusion. Previous proposed algorithms can only detect conflicts afterward instead of preventing them in advance. Therefore we propose a new architecture to avoid conflicts and provide recovery mechanism. Finally, we implement these functionalities and the evaluation of performance shows that this architecture is realistic and practical. ©2007 IEEE.
Cite
CITATION STYLE
Sun, H. M., Chang, S. Y., Chen, Y. H., He, B. Z., & Chen, G. K. (2007). The design and implementation of IPSec conflict avoiding and recovering system. In IEEE Region 10 Annual International Conference, Proceedings/TENCON. https://doi.org/10.1109/TENCON.2007.4429003
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.