Policies in SNMPv3-based Management

نویسندگان

  • Salima Omari
  • Raouf Boutaba
  • Omar Cherkaoui
چکیده

Two important achievements in the network management area motivated the work presented in this paper. The first one is the wide acceptance of the policy concept and its introduction as a means for driving management procedures. The second concerns the capabilities brought by the version 3 of the SNMP protocol for configurable and secure network management. The deployment of SNMPv3 at equipment level allows henceforth concretizing the policy-driven management: Refining enterprise policies; and enforcing them down the managed network resources. This paper aims at integrating the policy concept into the SNMPv3 framework. It proposes a set of rules to map authorization policies to the VACM (View Based Access Control Model) standardized as part of the SNMPv3 management framework. Policy attributes are maintained in a configuration database local to the SNMPv3 entity and a new application is incorporated into the SNMPv3 entity to perform the mapping. This will ultimately allow manager and management applications to enforce enterprise authorization policies independently of the security model(s) implemented by SNMPv3 entities.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Directory Supported Management with SNMPv3

Data security and maintaining system integrity are the primary concerns pointed out by corporations and individuals when connecting to the Internet. To respond to this demand, the most recent agreed Internet management standard, SNMPv3, introduces new security features to make SNMPbased management ready for enterprise management. This is possible only if the SNMPv3 management framework is intro...

متن کامل

A Policy-Based Security Management Architecture Using XML Encryption Mechanism for Improving SNMPv3

Simple Network Management Protocol (SNMP) is the most widely-used network management protocol for TCP/IP-based networks. The functionality of SNMP was enhanced with the publication of SNMPv2. However, both versions of SNMPv1 and SNMPv2 lack security features, notably authentication and privacy. The SNMPv3 solves these deficiencies but it has some inefficiency to deal with the access, service re...

متن کامل

SIMULATION OF SNMPv3 TRAFFIC FLOW METER MIB USING ARENA SIMULATION MODELLING SOFTWARE

Simple Network Management Protocol version 3 is an extension of earlier versions addressing security and administration features of SNMP. SNMPv3 has additional features like different message format and defines new management information bases (MIB) for security, configuration, notification, view-based access control and proxy forwarding. Simulation of SNMPv3 traffic flow meter MIB has been car...

متن کامل

On the Multicasting Security of SNMPv3

SNMPv3, a simple network management protocol, is secure in unicasting communications (i.e., point-to-point or end-to-end transmission). Furthermore, a manager and an agent can authenticate and exchange secure transmission between each other with no time delay or replay. In this paper, we extend the SNMPv3 unicasting security solution to be applicable in multicasting applications. In addition, w...

متن کامل

Survey on SNMP in next genaration network

Network management is a process to control networks with great efficiency. So far, network management protocols have changed from SNMPv1, SNMPv2 to SNMPv3. This paper briefly compares and analyses these versions on SMI & MIB, protocol operation, security and access control. Besides, it thoroughly summarizes most research aspects of recent SNMP developments, especially the next generation networ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999