Prototyping Fast, Simple, Secure Switches for Etha

  • Authors:
  • Jianying Luo;Justin Pettit;Martin Casado;John Lockwood;Nick McKeown

  • Affiliations:
  • Stanford University;Stanford University;Stanford University;Stanford University;Stanford University

  • Venue:
  • HOTI '07 Proceedings of the 15th Annual IEEE Symposium on High-Performance Interconnects
  • Year:
  • 2007

Quantified Score

Hi-index 0.04

Visualization

Abstract

We recently published our proposal for Ethane: A cleanslate approach to managing and securing enterprise networks. The goal of Ethane is to make enterprise networks (e.g. networks in companies, universities, and home offices) much easier to manage. Ethane is built on the premise that the only way to manage and secure networks is to make sure we can identify the origin of all traffic, and hold someone (or some machine) accountable for it. So first, Ethane authenticates every human, computer and switch in the network, and tracks them at all times. Every packet can be immediately identified with its sender. Second, Ethane implements a network-wide policy language in terms of users, machines and services. Before a flow is allowed into the network, it is checked against the policy.