A SECURE ACTIVE NETWORK ENVIRONMENT ARCHITECTURE - REALIZATION IN SWITCHWARE

Citation
Ds. Alexander et al., A SECURE ACTIVE NETWORK ENVIRONMENT ARCHITECTURE - REALIZATION IN SWITCHWARE, IEEE network, 12(3), 1998, pp. 37-45
Citations number
44
Categorie Soggetti
Engineering, Eletrical & Electronic","Computer Science Hardware & Architecture","Computer Science Information Systems",Telecommunications
Journal title
ISSN journal
08908044
Volume
12
Issue
3
Year of publication
1998
Pages
37 - 45
Database
ISI
SICI code
0890-8044(1998)12:3<37:ASANEA>2.0.ZU;2-4
Abstract
An active network is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of su ch network infrastructures invites new security risks. Coping with the se security risks represents the most fundamental contribution of acti ve network research.;The security concerns can be divided into those w hich affect the network as a whole and those which affect individual e lements. It is clear that the element problems must be solved first, s ince the integrity of network-level solutions will be based on trust i n the network elements. In this article we describe the architecture a nd implementation of a Secure Active Network Environment (SANE), which we believe provides a basis for implementing secure network-level sol utions. We guarantee that a node begins operation in a trusted state w ith the AEGIS secure bootstrap architecture. We guarantee that the sys tem remains in a trusted state by applying dynamic integrity checks in the network element's runtime system, using a novel naming system, an d applying node-to-node authentication when needed.