Safety and security of programmable network infrastructures
Title | Safety and security of programmable network infrastructures |
Publication Type | Journal Articles |
Year of Publication | 1998 |
Authors | Alexander S, Arbaugh WA, Keromytis AD, Smith JM |
Journal | IEEE Communications Magazine |
Volume | 36 |
Issue | 10 |
Pagination | 84 - 92 |
Date Published | 1998/10// |
ISBN Number | 0163-6804 |
Keywords | Access control, error protection, IP networks, Multicast protocols, network architecture, network operating systems, network service model, operating system, Power system dynamics, Power system modeling, Power system reliability, programmable languages, programmable network infrastructures, programming languages, Proposals, Protection, reliability properties, Safety, Secure Active Network Environment, Security, security of data, service creation, service providers, Switches, telecommunication computing, telecommunication network reliability, Web and internet services |
Abstract | Safety and security are two reliability properties of a system. A “safe” system provides protection against errors of trusted users, while a “secure” system protects against errors introduced by untrusted users. There is considerable overlap between mechanisms to support each property. Requirements for rapid service creation have stimulated the development of programmable network infrastructures, where end users or service providers can customize the properties of a network infrastructure while it continues to operate. A central concern of potential users of such systems is their reliability and, most specifically, their safety and security. In this article we explain the impact the network service model and architecture have on safety and security, and provide a model with which policies can be translated into restrictions of a general system. We illustrate these ideas with the Secure Active Network Environment (SANE) architecture, which provides a means of controlling access to the functions provided by any programmable infrastructure |
DOI | 10.1109/35.722141 |