DocumentCode :
1399442
Title :
A secure active network environment architecture: realization in SwitchWare
Author :
Alexander, D.S. ; Arbaugh, William A. ; Keromytis, Angelos D. ; Smith, Jonathan M.
Author_Institution :
Pennsylvania Univ., Philadelphia, PA, USA
Volume :
12
Issue :
3
fYear :
1998
Firstpage :
37
Lastpage :
45
Abstract :
An active network is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of active network research. The security concerns can be divided into those which affect the network as a whole and those which affect individual elements. It is clear that the element problems must be solved first, since the integrity of network-level solutions will be based on trust in the network elements. In this article we describe the architecture and implementation of a secure active network environment (SANE), which we believe provides a basis for implementing secure network-level solutions. We guarantee that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture. We guarantee that the system remains in a trusted state by applying dynamic integrity checks in the network element´s runtime system, using a novel naming system, and applying node-to-node authentication when needed. The construction of an extended LAN is discussed
Keywords :
local area networks; network operating systems; packet switching; security of data; AEGIS secure bootstrap architecture; SANE; SwitchWare; architecture; dynamic integrity checks; extended LAN; implementation; integrity; network infrastructure; network infrastructures; network-level solutions; node; node-to-node authentication; ramming system; secure active network environment architecture; trusted state; Access protocols; Authentication; Collaboration; Communication switching; Functional programming; IP networks; Intelligent networks; Proposals; Switches; Web and internet services;
fLanguage :
English
Journal_Title :
Network, IEEE
Publisher :
ieee
ISSN :
0890-8044
Type :
jour
DOI :
10.1109/65.690960
Filename :
690960
Link To Document :
بازگشت