A Secure Active Network Environment architecture: Realization in SwitchWare

被引:42
作者
Alexander, DS [1 ]
Arbaugh, WA [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, CIS Dept, Philadelphia, PA 19104 USA
来源
IEEE NETWORK | 1998年 / 12卷 / 03期
关键词
D O I
10.1109/65.690960
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
An active network is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of active network research.;The security concerns can be divided into those which affect the network as a whole and those which affect individual elements. It is clear that the element problems must be solved first, since the integrity of network-level solutions will be based on trust in the network elements. In this article we describe the architecture and implementation of a Secure Active Network Environment (SANE), which we believe provides a basis for implementing secure network-level solutions. We guarantee that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture. We guarantee that the system remains in a trusted state by applying dynamic integrity checks in the network element's runtime system, using a novel naming system, and applying node-to-node authentication when needed.
引用
收藏
页码:37 / 45
页数:9
相关论文
共 44 条
[1]  
ALEXANDER DS, 1997, P 1997 ACM SIGCOMM C
[2]   A secure and reliable bootstrap architecture [J].
Arbaugh, WA ;
Farber, DJ ;
Smith, JM .
1997 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1997, :65-71
[3]  
ARBAUGH WA, 1998, IN PRESS NETW DIST S, P155
[4]  
ATKINSON R, 1995, 1826 RFC
[5]  
Atkinson R., 1995, 1825 RFC
[6]  
Black Richard, 1997, P 22 ANN C LOC COMP
[7]   Decentralized trust management [J].
Blaze, M ;
Feigenbaum, J ;
Lacy, J .
1996 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 1996, :164-173
[8]  
BRADEN R, 1997, 2208 RFC INT
[9]  
BRENDAN C, 1995, IEEE NETWORK JUL, P22
[10]  
CLARK PC, 1994, THESIS G WASHINGTON