Cuvillier Verlag

Publications, Dissertations, Habilitations & Brochures.
International Specialist Publishing House for Science and Economy

Cuvillier Verlag GmbH

De En Es
Skalierbare Autokonfiguration sabotageresistenter virtueller privater Netze

Hard Copy
EUR 38.00 EUR 36.10

E-book
EUR 0.00

Download
PDF (3.4 MB)

Skalierbare Autokonfiguration sabotageresistenter virtueller privater Netze (English shop)

Michael Roßberg (Author)

Preview

Table of Contents, Datei (45 KB)
Extract, Datei (110 KB)

A fast and secure flow of information is increasingly becoming the main criterion for the success of companies, public authorities and organisations. In order to use public networks for this purpose, virtual private networks (VPNs) are generally operated. However, their manual configuration and operation is laborious and potentially error-prone. This circumstance has led to the development of numerous autoconfiguration approaches, which to date, however, address neither resistance to sabotage nor robustness. The few scalable systems fail to meet even simple functional requirements, such as the use of private IP addresses. In the case of two approaches, glaring security deficiencies could even be demonstrated.

On this basis, a novel concept for an IPsec-based VPN autoconfiguration approach was developed in the course of this work. By dispensing with exposed systems, it provides the foundation for a scalable and highly available system. Essential to it is the support of indirectly connected VPN participants, that is, those which are reachable exclusively via others. In this, the security of the payload data is always guaranteed end-to-end, and with regard to availability it is possible, for example, to reroute traffic via third-party sites in the event of partial communication failures. In the design of the system it could be shown that optimal paths are found even without the broadcast of routing information, and how inconsistencies and partitioning can be avoided when embedding structured overlay networks into these transport networks.

Through the possibility of configuring indirect security associations, direct communication processes can be administratively permitted or prohibited almost arbitrarily. If direct security associations to endangered systems are thus dispensed with, it becomes possible to conceal the externally visible IP addresses of VPN nodes and thus to protect them effectively against DoS attacks. For this reason, a system was developed in the course of this work which is nevertheless able to construct topologies with demonstrable security properties at low administrative expense. Among other things, each VPN node is assigned an availability zone and direct communication is permitted only between certain zones.

ISBN-13 (Printausgabe) 3869557753
ISBN-13 (Hard Copy) 9783869557755
ISBN-13 (eBook) 9783736937758
Final Book Format A5
Language German
Page Number 223
Lamination of Cover glossy
Edition 1 Aufl.
Volume 0
Publication Place Göttingen
Place of Dissertation Ilmenau
Publication Date 2011-06-27
General Categorization Dissertation
Departments Informatics
Keywords self-configuration, VPN, IPsec, scalability, robustness, security, sabotage, availability, denial-of-service, DoS