| Departments | |
|---|---|
| Book Series (99) |
1415
|
| Nachhaltigkeit |
3
|
| Gesundheitswesen |
3
|
| Humanities |
2410
|
| Natural Sciences |
5428
|
| Mathematics | 229 |
| Informatics | 320 |
| Physics | 982 |
| Chemistry | 1371 |
| Geosciences | 131 |
| Human medicine | 246 |
| Stomatology | 10 |
| Veterinary medicine | 112 |
| Pharmacy | 147 |
| Biology | 837 |
| Biochemistry, molecular biology, gene technology | 121 |
| Biophysics | 25 |
| Domestic and nutritional science | 45 |
| Agricultural science | 1005 |
| Forest science | 201 |
| Horticultural science | 20 |
| Environmental research, ecology and landscape conservation | 148 |
| Engineering |
1821
|
| Common |
97
|
|
Leitlinien Unfallchirurgie
5. Auflage bestellen |
|
Table of Contents, Datei (45 KB)
Extract, Datei (110 KB)
A fast and secure flow of information is increasingly becoming the main criterion for the success of companies, public authorities and organisations. In order to use public networks for this purpose, virtual private networks (VPNs) are generally operated. However, their manual configuration and operation is laborious and potentially error-prone. This circumstance has led to the development of numerous autoconfiguration approaches, which to date, however, address neither resistance to sabotage nor robustness. The few scalable systems fail to meet even simple functional requirements, such as the use of private IP addresses. In the case of two approaches, glaring security deficiencies could even be demonstrated.
On this basis, a novel concept for an IPsec-based VPN autoconfiguration approach was developed in the course of this work. By dispensing with exposed systems, it provides the foundation for a scalable and highly available system. Essential to it is the support of indirectly connected VPN participants, that is, those which are reachable exclusively via others. In this, the security of the payload data is always guaranteed end-to-end, and with regard to availability it is possible, for example, to reroute traffic via third-party sites in the event of partial communication failures. In the design of the system it could be shown that optimal paths are found even without the broadcast of routing information, and how inconsistencies and partitioning can be avoided when embedding structured overlay networks into these transport networks.
Through the possibility of configuring indirect security associations, direct communication processes can be administratively permitted or prohibited almost arbitrarily. If direct security associations to endangered systems are thus dispensed with, it becomes possible to conceal the externally visible IP addresses of VPN nodes and thus to protect them effectively against DoS attacks. For this reason, a system was developed in the course of this work which is nevertheless able to construct topologies with demonstrable security properties at low administrative expense. Among other things, each VPN node is assigned an availability zone and direct communication is permitted only between certain zones.
| ISBN-13 (Printausgabe) | 3869557753 |
| ISBN-13 (Hard Copy) | 9783869557755 |
| ISBN-13 (eBook) | 9783736937758 |
| Final Book Format | A5 |
| Language | German |
| Page Number | 223 |
| Lamination of Cover | glossy |
| Edition | 1 Aufl. |
| Volume | 0 |
| Publication Place | Göttingen |
| Place of Dissertation | Ilmenau |
| Publication Date | 2011-06-27 |
| General Categorization | Dissertation |
| Departments |
Informatics
|
| Keywords | self-configuration, VPN, IPsec, scalability, robustness, security, sabotage, availability, denial-of-service, DoS |