Improving packet filters management through automatic and dynamic schemes

Research output: Contribution to journalArticlepeer-review

Abstract

The development of complex access control architectures raises the problem of their management. In this article, we describe an architecture providing packet filters automatic configuration in Internet based networks. Our architecture improves existing proposals in three different fields. It suppresses the security officer interactions with the management architecture when topology changes occur thus preventing temporary security holes. Moreover our architecture proposes three optimisations to provide the access control processes with efficient configurations. Simulations show that the complexity of these configurations is close to the complexity found in configurations created by hand. Finally we describe how the notion of access control integrity can be incorporated in our management architecture at a reasonable cost.

Original languageEnglish
Pages (from-to)595-608
Number of pages14
JournalAnnales des Telecommunications/Annals of Telecommunications
Volume56
Issue number9-10
Publication statusPublished - 1 Jan 2001
Externally publishedYes

Keywords

  • Distributed system
  • Filtering
  • Integrity
  • Internet
  • Network architecture
  • Network management
  • Network router
  • Packet transmission
  • Simulation
  • Telecommunication network

Fingerprint

Dive into the research topics of 'Improving packet filters management through automatic and dynamic schemes'. Together they form a unique fingerprint.

Cite this