首页> 外文期刊>International journal of communication systems >Novel method for transferring access control list rules to synchronize security protection in a locator/identifier separation protocol environment with crossâ€segment host mobility
【24h】

Novel method for transferring access control list rules to synchronize security protection in a locator/identifier separation protocol environment with crossâ€segment host mobility

机译:用于传输访问控制列表规则的新方法,以将带有跨段主机移动性的定位器/标识符分离协议环境中的安全保护同步安全保护

获取原文
获取原文并翻译 | 示例
           

摘要

Extended access control lists (ACLs) are used to filter packets for network security. However, in current network frameworks, ACL rules are not transferred simultaneously with devices that move across network segments. The Internet Engineering Task Force proposed the Locator/Identifier Separation Protocol (LISP), which enables routers (xTRs) to configure ACL rules for blocking immobile endpoint identifiers (EIDs). However, when an EID moves from the original xTR to a new xTR, the ACL rules at the original xTR cannot be transferred with the EID. Thus, the new xTR lacks the corresponding ACL rules to effectively block the EID, resulting in security risks. The highlights of this study are as follows. First, a method is proposed for dynamically transferring ACL rules in LISP environments and frameworks. Second, the map-register and map-notify protocols were combined to encapsulate and transfer the ACL rules and thus obviate an additional process required to transfer these rules. Third, the experimental results verified that the proposed method can be used to achieve synchronized security protection in an LISP environment involving cross-segment EID movements.
机译:扩展访问控制列表(ACL)用于过滤网络安全的数据包。但是,在当前的网络框架中,ACL规则不会与跨网络段移动的设备同时传输。 Internet工程任务组提出了定位器/标识符分离协议(LISP),其使路由器(XTR)能够配置用于阻止Immobile Endpoint标识符(EID)的ACL规则。但是,当EID从原始XTR移动到新XTR时,原始XTR处的ACL规则无法使用EID传输。因此,新XTR缺少相应的ACL规则,以有效阻止EID,从而导致安全风险。本研究的亮点如下。首先,提出了一种方法,用于在LISP环境和框架中动态传输ACL规则。其次,地图寄存器和地图通知协议被组合为封装和传输ACL规则,从而避免了传输这些规则所需的附加过程。第三,实验结果证实,所提出的方法可用于在涉及交叉段EID运动的LISP环境中实现同步安全保护。

著录项

相似文献

  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号