Secure Quality of Service Handling: SQoSH

نویسندگان

  • D. Scott Alexander
  • William A. Arbaugh
  • Angelos D. Keromytis
  • Steve Muir
  • Jonathan M. Smith
چکیده

Proposals for programmable network infrastructures, such as active networks and open signaling, provide programmers with access to network resources and data structures. The motivation for providing these interfaces is accelerated introduction of new services, but exposure of the interfaces introduces many new security risks. The risks can be reduced or eliminated via appropriate restrictions on the exported interfaces. In this article we describe some of the security issues raised by active networks. We then describe our secure active network environment architecture. SANE was designed as a security infrastructure for active networks, and was implemented in the SwitchWare architecture. SANE restricts the actions loaded modules (including “capsules”) can perform by restricting the resources that can be named; this is further extended to remote invocation by means of cryptographic credentials. SANE can be extended to support restricted control of quality of service in a programmable network element. The Piglet lightweight device kernel provides a “Virtual Clock” type of scheduling discipline for network traffic, and exports several tuning knobs with which the clock can be adjusted. The ALIEN active loader provides safe access to these knobs to modules that operate on the network element. Thus, the proposed SQoSH architecture is able to provide safe, secure access to network resources, while allowing these resources to be managed by end users needing customized networking services. A desirable consequence of SQoSH’s integration of access control and resource control is that a large class of denial-of-service attacks, unaddressed solely with access control and cryptographic protocols, can now be prevented.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Optimising multimedia transmission in IP based wireless networks

Following the path opened by GSM systems, the under deployment UMTS system is leading to more and more configurable, dependable, adaptable, intelligent, secure but also complex wireless solutions. Aiming at handling digital data of different nature (text, voice, image, video, ...) that will be used in various contexts (home, office, on the move, ...) these systems rely on inner software that ma...

متن کامل

Handling Topology Updates in a Dynamic Tool for Support of Bandwidth on Demand Service

Automated Bandwidth Allocation across Heterogeneous Networks (AutoBAHN) is a tool under active development that supports a Bandwidth on Demand (BoD) service, intended to operate in a multi-domain environment using heterogeneous transmission technologies. The AutoBAHN system aims at providing a guaranteed capacity, connection-oriented service between two end points. Due to the distributed nature...

متن کامل

A Trustful Routing Protocol for Ad-hoc Network

Mobile Ad-hoc Network (MANET) is a wireless system that comprises mobile nodes. It is usually referred to a decentralized autonomous system. Self configurability and easy deployment feature of the MANET resulted in numerous applications in this modern era. Its routing protocol has to be able to cope with the new challenges that a MANET creates such as nodes mobility, security maintenance, and q...

متن کامل

A Secure Cluster-Based Multipath Routing Protocol for WMSNs

The new characteristics of Wireless Multimedia Sensor Network (WMSN) and its design issues brought by handling different traffic classes of multimedia content (video streams, audio, and still images) as well as scalar data over the network, make the proposed routing protocols for typical WSNs not directly applicable for WMSNs. Handling real-time multimedia data requires both energy efficiency a...

متن کامل

Emergency department flow in an optimized setting

Background The patterns of patient admission and discharge rarely reflects patient needs. The main reason is the way we manage processes such as ward rounds, operations, radiology, outpatient handling, inpatient tests etc. This results in variable length of stay (LoS) in the emergency departments, even among patients admitted with similar conditions. We have implemented structured time-driven p...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000