Research on IPSec inter-policy conflict discovering based on formal modeling technology

Jun Jie Huang · Jisuanji gongcheng yu sheji · 2007

Based on formal modeling technology and ordered binary decision diagrams,a generic model that captures various filtering policy semantics using Boolean expressions is presented.The model is used to derive a canonical representation for IPSec policies using ordered binary decision diagrams.A comprehensive framework is developed to classify and identify conflicts that could exist in a single IPSec device(intra-policy conflicts) in enterprise networks.The test and evaluation study on different network environments demonstrates the effectiveness and efficiency of the approach.

Read the paper · More papers on PaperTik