Security in Programmable Netword Infrastructures: The Integration of Network and Application Solutions

  • Authors:
  • Paolo Bellavista;Antonio Corradi;Rebecca Montanari;Cesare Stefanelli

  • Affiliations:
  • -;-;-;-

  • Venue:
  • IWAN '00 Proceedings of the Second International Working Conference on Active Networks
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

Programming the network infrastructure significantly enhances its flexibility and favors fast deployment of new protocols, but also introduces serious security risks. It is crucial to protect the whole distributed infrastructure, especially its availability in case of denial-of-service attacks. A security framework for programmable networks may provide security solutions at different levels of abstraction. Active networks mainly propose a network-layer approach, by extending the packet format to include security information. Mobile code technologies tend to provide security tools at the application layer to integrate with standard external infrastructures, such as public key ones. The paper describes the security frameworks of several programmable network proposals and points out the dis/advantages related to the adopted abstraction level. This comparison suggests to consider an integrated security framework capable of choosing the service-specific balance between application-layer flexibility and network efficiency. To this purpose, the paper presents the architecture of a Programmable Network Component (PNC) that integrates security solutions at different layers and that has been implemented by using a mobile agent programming environment.