Information Model for Policy-Based Network Security Management

  • Authors:
  • Sook-Yeon Kim;Myung-Eun Kim;Kiyoung Kim;Jongsoo Jang

  • Affiliations:
  • -;-;-;-

  • Venue:
  • ICOIN '02 Revised Papers from the International Conference on Information Networking, Wireless Communications Technologies and Network Applications-Part I
  • Year:
  • 2002

Quantified Score

Hi-index 0.01

Visualization

Abstract

Policy Based Network Management (PBNM) for network security has been paid much attention as a solution to consistent and unified management of security systems including IDS (Intrusion Detection System) and Firewall. In this paper, we define NSPIM (Network Security Policy Information Model) as a framework of representation, edition, store, and reuse of policies for intrusion detection and response in the PBNM. NSPIM forces each component of PBNM for network security to be flexible and extensible. NSPIM induces the operational structure of PMT (Policy Management Tool) and the data schema of PR (Policy Repository). In addition, policy provisioning objects between PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be defined based on NSPIM.