Proceedings of Freenix Track: 2000 Usenix Annual Technical Conference P O L I C Y E N F O R C E M E N T

نویسندگان

  • M E N T
  • Angelos D. Keromytis
  • Jason L. Wright
چکیده

Recent work in the area of network security, such as IPsec, provides mechanisms for securing the traÆc between any two interconnected hosts. However, it is not always possible, economical, or even practical from an administration and operational point of view to upgrade the software and con guration of all the nodes in a network to support such security protocols. One apparent solution to this problem is the use of security gateways that apply the relevant security protocols on behalf of the protected nodes, under the assumption that the \last hop" between the security gateway and the end node is safe without cryptography. Such a gateway can be set to enforce speci c security policies for di erent types of traÆc. While this solution is appealing in static scenarios (such as building so-called \intranets"), the use of Layer-3 (network) routers as security gateways presents some transparency and con guration problems with regards to peer authentication in the automated key management protocol. This paper describes the architecture and implementation of a Layer-2 (link layer) bridge with extensions for o ering Layer-3 security services. We extend the OpenBSD ethernet bridge to perform simple IP packet ltering and IPsec processing for incoming and outgoing packets on behalf of a protected node, completely transparently to both the protected and the remote communication endpoint. The same mechanism may be used to construct \virtual local area networks," by establishing IPsec tunnels between OpenBSD bridges connected geographically separated LANs. As our system operates in the link layer, there is no need for software or con guration changes in the protected nodes.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Amitraz Poisoning; A case study

A m i t r a z, a n i ns e c t i c i d e /a ca ri c i de of the f o r m a m i d i n e p e st i c i d e s group, is a ? 2 a d r e n e r g i c ag on i st a nd of t he a m i d i ne c h e m i ca l f a m il y generally us e d to c o n t r ol animal e c top a r a s i t e s. Poisoning due to am i t r a z i s r a r e and character...

متن کامل

Proceedings of Freenix Track: 2000 Usenix Annual Technical Conference a C C E P T ( ) S C a L a B I L I T Y O N L I N U X Accept() Scalability on Linux

This report explores the possible effects of a "thundering herd" problem associated with the Linux implementation of the POSIX accept() system call. We discuss the nature of the problem and how it may affect the scalability of the Linux kernel. In addition, we identify candidate solutions and considerations to keep in mind. Finally, we present a solution and benchmark it, giving a description o...

متن کامل

مطالعه فراوانی تیپ های مسمومیتزای انسانی کلستریدیوم بوتولینوم (A, B, E) در بعضی از ماهیان دریای شمال( سفید و کفال) و ماهیان دریای جنوب ( شوریده و حلوا) ایران

. (vr"+ ) lt s o{,9^is (Jt"j)Jtise r^il3tpb :oUle+ .,jti I dlir..9* db* s9"9 jJ j | .+1,. er- )LAe.1 I +.i9r; lf ' :.p9, .Lgr;lortjr;rlt, (a;r"; f f. VS),rilt9 !)9) air.ir)J) e 4y e+ yql*S JL;,r ol.icJ5 6lndit i . r;ii,S,lr! aiJ";icr9. a-i.1 oif6-f- r.r-f ortir-l t 9 ac!,51!!;,*Sf ,:t*- o:.J.i1 trS".* f q rg rf ,r- },l'j*.Ft . r,:f;.s.; ;oJi :ni 5rlJUrl Jylgig"dLbO*Ji,riijl cdlGglii reJJg...

متن کامل

شناسایی دگرگونی ژنتیکی در ویروس تب برفکی تیپ A با استفاده از تعیین ردیف نوکلئوتیدی قسمتی از ژن VP1 ویروس

,1s1ya:.J'$n :7tb !9y.tu;1 9; q 5t'1& p I r lt 4!lr 9 61,; .l.iy c.!! ob lr+ : tt 4jr.'j .Al JLrob.;qrolr,J'fll t q ..rlaLr. 4 RT-PCR ri,Sle 1r o.ri 6bi!l Jt-t5 RIA :.pe, .pe1 *q&,.5b.'.;9; VPr Oijl ,r,iiqo-f .ddisl-t,r-a.ttJ nlceloltl Jlhr""gbyp,glrrsc*l . d,ri$ multiplexRT-PCR cycle sequencing cie) jlosu:pl t r PCR Jr-e .ri . 'r-JJl9; a{.Jt Fluorescent dye deoxy-terminator ar.bgy.5bai...

متن کامل

تاثیر مرکزی هیستامین بر درد فرمالینی در خرگوش: نقش سیستم اپیوئیدی

.yiU s1 r qdJ 9 6!r.1 l,-r,iU 61 r,r1.11 ;oal il go,-7^19 ai f * *,-) S '*{'?'J*'fL' t:::tc: l/'2f /2 g.6;gb.t e*)* +r-,JifF.'L!.p"i9 r:.",ii:oul9+ 'Fft s ;J"r.pbjr;^*f- $ J9b +9 ll o;lr"iJ$!l odjUll Jt'56rlr2lr.! :rti9, ,(Jt;5) O*Jt"Jt i,;;ia.rJ1.pll oQr.i; nlCel ."r95f a+1,,r-..;ta 4..59L*yrtirlrcrbtUg i*r..p.259Fl'tfA,lflA.;lLirl,r6ek- 5r crrt!"rlr (efs.s..o' ) o*:..i1 Ji (.fsfefa),-;...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000