DocumentCode
2538835
Title
A new framework for secure network management
Author
Hatefi, Farid G. ; Golshani, Forouzan
Author_Institution
Dept. of Comput. Sci. & Eng., Arizona State Univ., Tempe, AZ, USA
fYear
1997
fDate
22-25 Sep 1997
Firstpage
510
Lastpage
515
Abstract
We introduce a new protocol, SNMS (secure network management system) with four primary goals. First, it uses encryption to establish a secure channel between a network manager and a network agent. Second, it allows network management tasks to be performed from any station on the network. Third, it enables a manager to remotely add manageable objects to an agent. Finally, it makes a prototype along with a set of guidelines to make the transition from SNMP (simple network management protocol) to SNMS. The SNMS combines features from HTTP (hyper text transfer protocol), SSL (secure socket layer) security mechanism, and CGI (common gateway interface) programming techniques, and deals with the entire Web client/server paradigm. Network managers can securely monitor and control the network elements from any station on the network. Compared with SNMP, which does not provide any safety measures for exchanging information between a manager and an agent, the SNMS offers a high degree of security by encrypting all the traffic between the manager and an agent. The SNMS applies public key and private key encryption and decryption with a mixture of digital signature and two way authentication
Keywords
Internet; computer network management; decoding; message authentication; protocols; public key cryptography; HTTP; SNMP; SNMS; Web client/server; common gateway interface programming; decryption; digital signature; encryption; hyper text transfer protocol; manageable objects; network agent; network elements control; network elements monitoring; network manager; private key encryption; public key encryption; secure channel; secure network management; secure network management system; secure socket layer security; simple network management protocol; two way authentication; Cryptography; Guidelines; Information security; Monitoring; Network servers; Protocols; Prototypes; Safety; Sockets; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Communications and Networks, 1997. Proceedings., Sixth International Conference on
Conference_Location
Las Vegas, NV
ISSN
1095-2055
Print_ISBN
0-8186-8186-1
Type
conf
DOI
10.1109/ICCCN.1997.623360
Filename
623360
Link To Document