Most active networking research so far has focused on infrastructure issues, such as redefining system structures and interfaces, with a limited application context to drive development. This has led to a rich selection of node operating systems and execution environments, but mostly simple applications that have not exploited the underlying functionality to its full potential. In this paper we take the application perspective, focusing our attention on using active networking technology to solve outstanding real-world problems. We identify problems in the areas of tra#c analysis, accounting, and denial of service attack detection/prevention, and present solutions based on a lightweight active substrate. We demonstrate how such network management problems can be solved, and how they benefit from programmability with respect to flexibility, security and ease of deployment.
|
867
|
Security architecture for the internet protocol
– Kent, Atkinson
- 1998
|
|
597
|
The KeyNote Trust-Management
– Blaze, Feigenbaum, et al.
|
|
592
|
Efficient software-based fault isolation
– Wahbe, Lucco, et al.
- 1993
|
|
445
|
A survey of active network research
– Tennenhouse, Smith, et al.
- 1997
|
|
438
|
TCP and explicit congestion notification
– Floyd
- 1994
|
|
425
|
The BSD Packet Filter: A New Architecture for User-Level Packet Capture
– McCanne, Jacobson
- 1993
|
|
374
|
Practical Network Support for IP Traceback
– Savage, Wetherall, et al.
- 2000
|
|
354
|
Proposal to add explicit congestion notification (ecn
– Ramakrishnan, Floyd
- 1999
|
|
326
|
The Stanford FLASH Multiprocessor
– Kuskin, Ofelt, et al.
- 1994
|
|
184
|
Distributed management by delegation
– Goldszmidt, Yemini
- 1995
|
|
171
|
Implementing Pushback: Router-Based Defense Against DDoS Attacks
– Ioannidis, Bellovin
- 2002
|
|
158
|
Controlling high bandwidth aggregates in the network
– Manajan, Bellovin, et al.
|
|
148
|
An Algebraic Approach to IP Traceback
– Dean, Franklin, et al.
|
|
138
|
An architecture for largescale Internet measurement
– Paxson, Mahdavi, et al.
- 1998
|
|
125
|
Trajectory sampling for direct traffic observation
– Duffield, Grossglauser
- 2000
|
|
73
|
ICMP traceback messages
– Bellovin
- 2000
|
|
65
|
OC3MON: Flexible, Affordable, High Performance Staistics Collection
– Apisdorf, Claffy, et al.
- 1996
|
|
63
|
A framework for alternate queueing: Towards traffic management by PC-UNIX based routers
– Cho
- 1998
|
|
61
|
An architecture for di€erentiated services
– Blake, Black, et al.
- 1998
|
|
54
|
Activating networks: A progress report
– Smith, Calvert, et al.
- 1999
|
|
52
|
An extensible probe architecture for network protocol performance measurement
– Malan, Jahanian
- 1998
|
|
44
|
The KeyNote Trust
– Blaze, Feigenbaum, et al.
- 1999
|
|
32
|
Traffic Flow Measurement: Experiences with NeTraMet
– Brownlee
- 1997
|
|
27
|
An active network approach for efficient network management
– Raz, Shavitt
- 1999
|
|
25
|
Anonymous RPC: Low-latency protection in a 64bit address space
– Yarvin, Bukowski, et al.
- 1993
|
|
22
|
Sub-Operating Systems: A New Approach to Application Security
– Ioannidis, Bellovin, et al.
- 2002
|
|
17
|
Effective Traffic Measurement using NTOP
– Deri, Finsiel, et al.
- 1999
|
|
16
|
Implementing IPsec
– Keromytis, Ioannidis, et al.
- 1948
|
|
12
|
An ECN-based end-to-end congestioncontrol framework: experiments and evaluation
– Laevens, Key, et al.
- 2000
|
|
10
|
Advanced and authenticated techniques for ip traceback
– Song, Perrig
- 2001
|
|
9
|
OC3MON: Flexible, Aordable, High Performance Statistics Collection
– Apisdorf, Clay, et al.
- 1997
|
|
6
|
The switchware active network implementation
– Alexander, Hicks, et al.
- 1998
|
|
5
|
A framework for alternate queueing: towards trac management by pc-unix based routers
– Cho
- 1998
|
|
5
|
Trajectory sampling for direct trac observation
– Dueld, Grossglauser
- 2000
|
|
5
|
A Proposal to add Explicit Congestion Noti cation (ECN) to IP
– Ramakrishnan, Floyd
- 1999
|
|
5
|
An active network approach for ecient network management
– Raz, Shavitt
- 1999
|
|
5
|
and Yuval Shavitt, “New models and algorithms for programmable networks
– Raz
- 1999
|
|
3
|
E#ective Tra#c Measurement using NTOP
– Deri, Suin
- 2000
|
|
3
|
Philippe Owezarski, Dina Papagiannaki, and Fouad Tobagi. Design and Deployment of a Passive Monitoring Infrastructure
– Fraleigh, Diot, et al.
- 2001
|
|
2
|
Measurement-based admission control
– Grossglauser, Tse
- 1997
|
|
2
|
CERT Advisory CA-1996-21: TCP SYN Flooding and IP Spoofing Attacks
– Pages
- 1996
|
|
2
|
Fouad Toba gi. Architecture of a Passive Monitoring System for IP Networks
– Fraleigh, Moon, et al.
- 2000
|
|
1
|
NetFlow services and applications. (white paper), http://www.cisco.com/warp/public/cc/pd/iosw/ioft/netflct/tech/napps - wp.htm
– Corporation
- 2000
|
|
1
|
The multiprocessor
– Kuskin, Ofelt, et al.
- 1994
|
|
1
|
Managing the Performance of Networked Applications. (white paper), http://www.netiq.com/downloads/library /SolutionSheets/NetIQNetworkSolutions.pdf
– Corporation
- 2001
|