Improving the configuration management of large network security systems

  • Authors:
  • João Porto de Albuquerque;Holger Isenberg;Heiko Krumm;Paulo Lício de Geus

  • Affiliations:
  • Institute of Computing, State University of Campinas, Campinas, SP, Brazil;FB Informatik, University of Dortmund, Dortmund, Germany;FB Informatik, University of Dortmund, Dortmund, Germany;Institute of Computing, State University of Campinas, Campinas, SP, Brazil

  • Venue:
  • DSOM'05 Proceedings of the 16th IFIP/IEEE Ambient Networks international conference on Distributed Systems: operations and Management
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The security mechanisms employed in today's networked environments are increasingly complex and their configuration management has an important role for the protection of these environments. Especially in large scale networks, security administrators are faced with the challenge of designing, deploying, maintaining, and monitoring a huge number of mechanisms, most of which have complicated and heterogeneous configuration syntaxes. This work offers an approach for improving the configuration management of network security systems in large-scale environments. We present a configuration process supported by a modelling technique that uniformly handles different mechanisms and by a graphical editor for the system design. The editor incorporates focus and context concepts for improving model visualisation and navigation.