The price of safety in an active network

被引:12
作者
Alexander, DS [1 ]
Menage, PB
Keromytis, AD
Arbaugh, WA
Anagnostakis, KG
Smith, JM
机构
[1] Activium Inc, New York, NY USA
[2] Ensim Corp, Sunnyvale, CA USA
[3] Univ Penn, Philadelphia, PA 19104 USA
[4] Univ Maryland, College Pk, MD 20742 USA
关键词
Active Networking; security; performance;
D O I
10.1109/JCN.2001.6596875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security is a major challenge for "Active Networking" as accessible programmability creates numerous opportunities for mischief. The point at which programmability is exposed, e,g,, through the loading and execution of code in network elements, must therefore be carefully crafted to ensure security. The SwitchWare active networking research project has studied the architectural implications of various tradeoffs between performance and security. Namespace protection and type safety were achieved with a module loader for active networks, ALIEN, which carefully delineated boundaries for privilege and dynamic updates. ALIEN supports two extensions, the Secure Active Network Environment (SANE), and the Resource Controlled Active Network Environment (RCANE). SANE extends ALIEN's node protection model into a distributed setting, and uses a secure bootstrap to guarantee integrity of the namespace protection system. RCANE provides resource isolation between active network node users, including separate heaps and robust time-division multiplexing of the node. The SANE and RCANE systems show that convincing active network security can be achieved. This paper contributes a measurement-based analysis of the costs of such security with an analysis of each system based on both execution traces and end-to-end behavior.
引用
收藏
页码:4 / 18
页数:15
相关论文
共 44 条
[1]   Safety and security of programmable network infrastructures [J].
Alexander, DS ;
Arbaugh, WA ;
Keromytis, AD ;
Smith, JM .
IEEE COMMUNICATIONS MAGAZINE, 1998, 36 (10) :84-+
[2]   A Secure Active Network Environment architecture: Realization in SwitchWare [J].
Alexander, DS ;
Arbaugh, WA ;
Keromytis, AD ;
Smith, JM .
IEEE NETWORK, 1998, 12 (03) :37-45
[3]  
ALEXANDER DS, 1999, P 1 INT WORK C ACT N
[4]  
ALEXANDER DS, 1997, MSCIS9717 PENNS U
[5]  
ALEXANDER DS, 1997, P ACM SIGCOMM SEPT
[6]  
ALEXANDER DS, 1998, THESIS PENNSYLVANIA
[7]  
[Anonymous], 2522 RFC
[8]   GARBAGE COLLECTION CAN BE FASTER THAN STACK ALLOCATION [J].
APPEL, AW .
INFORMATION PROCESSING LETTERS, 1987, 25 (04) :275-279
[9]   A secure and reliable bootstrap architecture [J].
Arbaugh, WA ;
Farber, DJ ;
Smith, JM .
1997 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1997, :65-71
[10]  
ARBAUGH WA, 1998, S NETW DISTR SYST SE