Research on Network Security Based on IPSec
Yanru Liu
Abstract
Open-access reader
Yanru Liu
Abstract
Open-access reader
With the development of information technology, Network security issues are very prominent, Network security incidents occur frequently.In order to enhance network security, we must take certain measures that are the use of IP protocol.IP protocol also called Internet Protocol.As defined in the network layer in the internet important agreement, is the current implementation of the network communication between the computer requirements.As a security model, IPSec is based on end-to-end trust and security between the source IP address and the destination IP address.IPSec network transmission protocol is developed mainly to solve the network layer security issues, and IP protocol to improve the confidentiality and integrity.It is necessary to apply the IPSec to the new IPv6 network protocol.Through the use of IPSec, you can build a more secure and reliable network environment, which provides more spaces for the development of the Internet and ecommerce. The Importance of Network SecurityFrom the 1998, the period of rapid development of the Internet to the present, with the constant development of information technology, Network information security has become a hot topic in the 21st century.Network security issues emerge in an endless stream, such as in August 2003, the virus of worms make use of Microsoft's system vulnerabilities attack 80% of the global Windows users.There are many examples in China, such as Panda case.In the 2015 China Internet Network Security Report that published in May 25 2015, network security incidents up to 12,616, that's a 125.9% increase on last year.At present, the Internet develops rapidly, but the corresponding speed of security measures cannot keep up.Network security incidents occur frequently; we should realize the seriousness of this problem and strengthen the research of Network Security.Using IPSec to guarantee network security.The full name of IPSec is Internet Protocol Security.It is an effective method to solve the network security problems.IPSec can provide a variety of security services, mainly includes the following aspects: data privacy, data integrity based on a connectionless, packet source authentication, access control, anti-retry attacks, privatization and some degree of data traffic.The above-mentioned security services are mainly achieved through the two security protocols, ESP (Encapsulating Security Payload) and AH (Authentication Header).There are two ways to implement Internet protocol security.The first one is to achieve in the gateway.The second one is to implement on the host.However, regardless of which method to implement IPSec, when the IPSec interface has an IP packet to enter or leave, IPSec will take different treatment to this package based on the SPD (Security Policy Database).There are three kinds of IP packet processing in IPSec: drop, bypass, and IPSec processing according to the security association.It is particularly easy to implement for the access control security of the firewall in IPv4.When an IP packet is sent to an interface, the first step is to look at the properties of the IP packet and the associated security settings.And then to find the appropriate security settings in the SAD (Security Association Database), decode this IP packet, then you can find the corresponding security policy stored in the SPD.Then you can find the corresponding security policy stored in and SPD.If the security policy of IP packet can be found in SPD, we should deal with the IP packet in accordance with the provisions of security policy, generally divided into three cases, the first way is discarded.It means that deal with the package in accordance with the regulation, at the same time, logs are also logged.The second way is bypassed.The so-called bypass is to let the IP packet through, and don't do other processing.The third way is IPSec processing.The main dealing way is
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
With the development of information technology, Network security issues are very prominent, Network security incidents occur frequently.In order to enhance network security, we must take certain measures that are the use of IP protocol.IP protocol also called Internet Protocol.As defined in the network layer in the internet important agreement, is the current implementation of the network communication between the computer requirements.As a security model, IPSec is based on end-to-end trust and security between the source IP address and the destination IP address.IPSec network transmission protocol is developed mainly to solve the network layer security issues, and IP protocol to improve the confidentiality and integrity.It is necessary to apply the IPSec to the new IPv6 network protocol.Through the use of IPSec, you can build a more secure and reliable network environment, which provides more spaces for the development of the Internet and ecommerce. The Importance of Network SecurityFrom the 1998, the period of rapid development of the Internet to the present, with the constant development of information technology, Network information security has become a hot topic in the 21st century.Network security issues emerge in an endless stream, such as in August 2003, the virus of worms make use of Microsoft's system vulnerabilities attack 80% of the global Windows users.There are many examples in China, such as Panda case.In the 2015 China Internet Network Security Report that published in May 25 2015, network security incidents up to 12,616, that's a 125.9% increase on last year.At present, the Internet develops rapidly, but the corresponding speed of security measures cannot keep up.Network security incidents occur frequently; we should realize the seriousness of this problem and strengthen the research of Network Security.Using IPSec to guarantee network security.The full name of IPSec is Internet Protocol Security.It is an effective method to solve the network security problems.IPSec can provide a variety of security services, mainly includes the following aspects: data privacy, data integrity based on a connectionless, packet source authentication, access control, anti-retry attacks, privatization and some degree of data traffic.The above-mentioned security services are mainly achieved through the two security protocols, ESP (Encapsulating Security Payload) and AH (Authentication Header).There are two ways to implement Internet protocol security.The first one is to achieve in the gateway.The second one is to implement on the host.However, regardless of which method to implement IPSec, when the IPSec interface has an IP packet to enter or leave, IPSec will take different treatment to this package based on the SPD (Security Policy Database).There are three kinds of IP packet processing in IPSec: drop, bypass, and IPSec processing according to the security association.It is particularly easy to implement for the access control security of the firewall in IPv4.When an IP packet is sent to an interface, the first step is to look at the properties of the IP packet and the associated security settings.And then to find the appropriate security settings in the SAD (Security Association Database), decode this IP packet, then you can find the corresponding security policy stored in the SPD.Then you can find the corresponding security policy stored in and SPD.If the security policy of IP packet can be found in SPD, we should deal with the IP packet in accordance with the provisions of security policy, generally divided into three cases, the first way is discarded.It means that deal with the package in accordance with the regulation, at the same time, logs are also logged.The second way is bypassed.The so-called bypass is to let the IP packet through, and don't do other processing.The third way is IPSec processing.The main dealing way is
Key concepts: IPsec, Computer science, Computer network, Computer security, Network security, Operating system, The Internet