Skip to Main Content
IETF has proposed a policy framework called policy-based network management (PBNM). Its best point is to provide automation of network configuration. Currently network area is actively embodying PBNM for QoS provisioning, RSVP admission control, device configuration, and etc. However, security area is not greatly interest in PBNM except IPSec. This paper proposes a PBNM-based security policy decision service, which can provide automation of security network configuration. The proposed policy decision service has capacity that can automatically create/activate a response policy rule on the basis of security status, activate a policy rule on the basis of rule timer, decide a security system best suitable to a policy rule, and select policy rules that should be applied to a security system.