SECURITY AND COLLABORATIVE ENFORCEMENT OF FIREWALL POLICIES IN VPNS
P. Jayarekha, Sunil Kalaburgi, M. Dakshayini · 2013
A virtual private network (VPN) is a private network that uses public network to connect remote sites. It enables host computer to send and receive data across shared or public network as if they were integral part of private network with all functionality, security and management policies of private network. To access organization network’s resource an encrypted VPN tunnel is formed between home network and foreign network. Although VPN technology is very useful, it brings down security threats on remote network because its firewall does not what traffic is flowing inside the VPN tunnel. To address this problem, VGuard was proposed, a frame work that allows a home network and a foreign network to collaboratively determine whether the request satisfies the policy without the home network knowing the request and the foreign network knowing the policy. In this paper we study a protocol called Xhash, which allows two parties, where each party has a key, to compare whether they have the same keys, without disclosing their keys to each other. VGuard frame work that uses Xhash as the basic building block. In order to make the existing approach better, this paper presents a DES-192 algorithm which uses 24 byte key input. This algorithm is used to increase the security among Policy Owner and Request Owner, which makes encryption algorithm more robust to attackers.