Závěrečná práce: Vít Labuda: Fine-grained access management for eduVPN
Bakalářská práce
Fine-grained access management for eduVPN
Anotace
Korektní řízení přístupu na úrovni sítě je zásadní pro zajištění bezpečnosti virtuálních privátních sítí (VPN), protože je mohou používat geograficky vzdálení klienti, jejichž fyzická bezpečnost může být snadno kompromitována. Systém eduVPN na Masarykově univerzitě se v současné době spoléhá na hrubozrnnou architekturu řízení přístupu založenou na profilech, která má několik limitací; proto je v této …více
Abstract
Proper network-level access controls are vital for ensuring the security of Virtual Private Networks (VPNs), as they may be used by geographically distant clients whose physical security may easily be compromised. The eduVPN system at Masaryk University currently relies on a coarse-grained, profile-based access control architecture, which has several limitations; therefore, a new, fine-grained architecture …více
Zadání práce
The thesis focuses on designing and implementing a proof-of-concept solution of a new access architecture in the eduVPN system, which will eliminate the need to manage multiple profiles and enable finer access control directly on the side of the eduVPN server.
The student will first familiarize themselves with the current deployment of eduVPN at Masaryk University, the means of user profile management, and their relation to identity management systems. Based on this information, they will design a proof-of-concept software implementing an architecture that uses a unified eduVPN profile for all users and controls access to specific services through local firewall rules on eduVPN nodes.
As part of the work, an interface for storing mappings of users to network services they are authorized to access will be designed and implemented. This interface will be designed so it can integrate with identity management systems which contain the necessary information about permissions. On the eduVPN server side, a process will be implemented that dynamically generates appropriate local firewall rules when a user connects, allowing them access only to permitted network services.
In the final part, the student will test the functionality of the solution, measure the impact of a large number of generated firewall rules on the performance and throughput of eduVPN nodes, and, based on the results obtained, evaluate whether this approach is suitable for further use within Masaryk University.
The created code will be publicly available in the IS under the BSD License 2.0.
22. 5. 2026 08:43, RNDr. Petr Velan, Ph.D., učo 255519
Přílohy
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Síťová bezpečnost základních škol
Mgr. Lukáš Nevařil, učo 98600 -
Výukový materiál pro předmět Síťová bezpečnost III
Patrik Mihálik -
Výukový materiál pro předmět Síťová bezpečnost III
Patrik Mihálik -
Komparativní analýza osobních firewallů
Mgr. Andrej Šimko, učo 359952 -
Delegovaná správa firewallu založená na identitách uživatelů
Mgr. Sven Relovský -
Small scale denial of service attacks
Mgr. Vít Bukač, Ph.D. -
Security Patterns Modelling
Ing. Zdeněk Sedláček -
Sledování a analýza kybernetických útoků
Mgr. Ondřej Koutský




