A Secure Active Network Environment Architecture
نویسندگان
چکیده
Active Networks are a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of Active Network research. The security concerns can be divided into those which affect the network as a whole and those which affect individual elements. It is clear that the element problems must be solved first, as the integrity of network-level solutions will be based on trust of the network elements. In this paper, we describe the architecture and implementation of a Secure Active Network Environment (SANE1), which we believe provides a basis for implementing secure network-level solutions. We guarantee that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture. We guarantee that the system remains in a trusted state by applying dynamic integrity checks in the network element's run time system, a novel naming system, and applying node-node authentication when needed. The SANE implementation is for x86 architectures, currently those running one of several varieties of UNIX. Comments University of Pennsylvania Department of Computer and Information Science Technical Report No. MSCIS-97-17. This technical report is available at ScholarlyCommons: http://repository.upenn.edu/cis_reports/114
منابع مشابه
A Mobile and Fog-based Computing Method to Execute Smart Device Applications in a Secure Environment
With the rapid growth of smart device and Internet of things applications, the volume of communication and data in networks have increased. Due to the network lag and massive demands, centralized and traditional cloud computing architecture are not accountable to the high users' demands and not proper for execution of delay-sensitive and real time applications. To resolve these challenges, we p...
متن کاملA Secure Active Network Environment Architecture Realization in SwitchWare
Active Networks is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of Active Network research. The security concerns can be divided into those which affect the network as a whole and those whic...
متن کاملPerformance Implications of Securing Active Networks
Security is an obvious risk to active networking, as increased flexibility creates numerous opportunities for mischief. The point at which this flexibility is exposed, e.g., through the loading of code into network elements, must therefore be carefully crafted to ensure security. The Secure Active Network Environment (SANE) architecture provides a secure bootstrap process resulting in a module ...
متن کاملA Flexible IP Active Networks Architecture
This paper presents the main concepts of the IST Project FAIN “Future Active IP Networks” [10], a three-year collaborative research project, whose main task is to develop and validate an open, flexible, programmable and dependable network architecture based on a novel active node approach. This generic architecture for active networks is an innovative integration of active networking, distribut...
متن کاملYAAP: Yet Another Active Platform
We present YAAP: a generic active network architecture with the ability to manually and dynamically deploy network services within distributed network nodes and providing a secure execution environment (EE). It also demultiplexes active network packets to multiple EEs located on the same network node. Currently, YAAP prototype is implemented under the Linux operating system, with some parts bui...
متن کامل