A Secure Active Network Environment architecture: Realization in SwitchWare

被引:42
|
作者
Alexander, DS [1 ]
Arbaugh, WA [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, CIS Dept, Philadelphia, PA 19104 USA
来源
IEEE NETWORK | 1998年 / 12卷 / 03期
关键词
D O I
10.1109/65.690960
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
An active network is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of active network research.;The security concerns can be divided into those which affect the network as a whole and those which affect individual elements. It is clear that the element problems must be solved first, since the integrity of network-level solutions will be based on trust in the network elements. In this article we describe the architecture and implementation of a Secure Active Network Environment (SANE), which we believe provides a basis for implementing secure network-level solutions. We guarantee that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture. We guarantee that the system remains in a trusted state by applying dynamic integrity checks in the network element's runtime system, using a novel naming system, and applying node-to-node authentication when needed.
引用
收藏
页码:37 / 45
页数:9
相关论文
共 50 条
  • [21] Active network architecture and management
    Ladner, Roy
    Warner, Elizabeth
    Katikaneni, Udaykiran
    McCreedy, Frank
    Petry, Frederick E.
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2007, 22 (10) : 1123 - 1138
  • [22] Towards an active network architecture
    Tennenhouse, DL
    Wetherall, DJ
    MULTIMEDIA COMPUTING AND NETWORKING 1996, 1996, 2667 : 2 - 16
  • [23] Secure IoT Architecture for Integrated Smart Services Environment
    Jerald, Vimal A.
    Rabara, Albert S.
    Bai, Daisy Premila
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 800 - 805
  • [24] Secure architecture for multicasting on active virtual private networks
    Labonte, C
    Sampalli, S
    MILCOM 2004 - 2004 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1- 3, 2004, : 301 - 307
  • [25] Lares: An architecture for secure active monitoring using virtualization
    Payne, Bryan D.
    Carbone, Martim
    Sharif, Monirul
    Lee, Wenke
    PROCEEDINGS OF THE 2008 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2008, : 233 - 247
  • [26] Study on Architecture and Realization of Ultra Media Network GIS
    Chen, Lin
    Liu, Jianfeng
    Zhang, Xiwang
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON RESOURCE ENVIRONMENT AND INFORMATION TECHNOLOGY IN 2010 (REIT' 2010), 2010, : 486 - 489
  • [27] A method to design process architecture in a distributed product realization environment
    Xiao, A
    Allen, JK
    Rosen, D
    Mistree, F
    IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 124 - 129
  • [28] SHINE: Secure Hybrid In Network caching Environment
    Romano, Simon Pietro
    Roseti, Cesare
    Tulino, Antonia Maria
    2018 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2018), 2018,
  • [29] Asymptotically Secure Network Code for Active Attacks
    Hayashi, Masahito
    Cai, Ning
    IEEE TRANSACTIONS ON COMMUNICATIONS, 2021, 69 (05) : 3245 - 3259
  • [30] Architecture and mechanisms for secure and efficient internetworking of heterogeneous network
    Luo H.
    Zhang S.
    Wang Z.
    Tongxin Xuebao/Journal on Communications, 2022, 43 (04): : 36 - 49