Efficient security management for active networks
Due to the dynamic nature and dynamic routing capability of active packets, security in active networks should be hop-by-hop based. This thesis discusses the identified drawbacks of existing approaches. These drawbacks are: the high performance overhead generated by per-hop Security Association (SA)...
Main Author: | |
---|---|
Published: |
University College London (University of London)
2007
|
Subjects: | |
Online Access: | http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.686672 |
id |
ndltd-bl.uk-oai-ethos.bl.uk-686672 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-bl.uk-oai-ethos.bl.uk-6866722017-10-04T03:13:30ZEfficient security management for active networksCheng, L. L. L.2007Due to the dynamic nature and dynamic routing capability of active packets, security in active networks should be hop-by-hop based. This thesis discusses the identified drawbacks of existing approaches. These drawbacks are: the high performance overhead generated by per-hop Security Association (SA) negotiation prior to secured active packet transmission the high complexity in SA negotiation handshake process active packet can only be securely transmitted after SA negotiations the shared key set generated for protecting active packets may not have Perfect Forward Secrecy (PFS) lack of confidentiality protection on exchanged symmetric keys and active packets lack of SA negotiation power and scalability issues. This thesis presents a novel hop-by-hop active network security management approach known as Security Protocol for Active Networks (SPAN). SPAN is designed to enable secure active packet transmission during a series of hop-by-hop SPAN SA negotiation along a new execution path, instead of after. The design of SPAN has taken into consideration the factors of security, efficiency, flexibility, scalability, and applicability. SPAN is resistant to replay, man-in-the-middle, impersonate attacks. SPAN is designed to detect DoS attacks much more efficiently. Furthermore, SPAN is uniquely designed to enhance the robustness and efficiency of underlying active networking systems.005.8University College London (University of London)http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.686672http://discovery.ucl.ac.uk/1445391/Electronic Thesis or Dissertation |
collection |
NDLTD |
sources |
NDLTD |
topic |
005.8 |
spellingShingle |
005.8 Cheng, L. L. L. Efficient security management for active networks |
description |
Due to the dynamic nature and dynamic routing capability of active packets, security in active networks should be hop-by-hop based. This thesis discusses the identified drawbacks of existing approaches. These drawbacks are: the high performance overhead generated by per-hop Security Association (SA) negotiation prior to secured active packet transmission the high complexity in SA negotiation handshake process active packet can only be securely transmitted after SA negotiations the shared key set generated for protecting active packets may not have Perfect Forward Secrecy (PFS) lack of confidentiality protection on exchanged symmetric keys and active packets lack of SA negotiation power and scalability issues. This thesis presents a novel hop-by-hop active network security management approach known as Security Protocol for Active Networks (SPAN). SPAN is designed to enable secure active packet transmission during a series of hop-by-hop SPAN SA negotiation along a new execution path, instead of after. The design of SPAN has taken into consideration the factors of security, efficiency, flexibility, scalability, and applicability. SPAN is resistant to replay, man-in-the-middle, impersonate attacks. SPAN is designed to detect DoS attacks much more efficiently. Furthermore, SPAN is uniquely designed to enhance the robustness and efficiency of underlying active networking systems. |
author |
Cheng, L. L. L. |
author_facet |
Cheng, L. L. L. |
author_sort |
Cheng, L. L. L. |
title |
Efficient security management for active networks |
title_short |
Efficient security management for active networks |
title_full |
Efficient security management for active networks |
title_fullStr |
Efficient security management for active networks |
title_full_unstemmed |
Efficient security management for active networks |
title_sort |
efficient security management for active networks |
publisher |
University College London (University of London) |
publishDate |
2007 |
url |
http://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.686672 |
work_keys_str_mv |
AT chenglll efficientsecuritymanagementforactivenetworks |
_version_ |
1718542837887270912 |