Download:
|
by Yongguang Zhang, Bikramjit Singh
Proceedings of 9th USENIX Security Symposium
http://www.wins.hrl.com/people/ygz/papers/usenix00.ps.gz
Add To MetaCart
Abstract:
IPsec [KA98c] is a suite of standard protocols that provides security services for Internet communications. It protects the entire IP datagram in an \end-to-end " fashion; no intermediate network node in the public Internet can access or modify any information above the IP layer in an IPsec-protected packet. However, recent advances in internet technology introduce a rich new set of services and applications, like trac engineering, TCP performance enhancements, or transparent proxying and caching, all of which require intermediate network nodes to access a certain part of an IP datagram, usually the upper layer protocol information, to perform ow classication, constraint-based routing, or other customized processing. This is in direct con-ict with the IPsec mechanisms. In this research, we propose a multi-layer security protection scheme for IPsec, which uses a ner-grain access control to allow trusted intermediate routers to read and write selected portions of IP datagrams (usually the headers) in a secure and controlled manner. 1
Citations
|
1681
|
Random Early Detection Gateways for Congestion Avoidance
– Floyd, Jacobson
- 1993
|
|
834
|
Security architecture for the Internet protocol
– Kent, Atkinson
- 1998
|
|
594
|
Promoting the Use of End-to-End Congestion Control in the Internet
– Floyd, Fall
- 1999
|
|
588
|
Kantz ”A comparison of mechanisms for Improving TCP Performance over Wireless Links
– Balakrishnan, Padmanabhan, et al.
|
|
216
|
The TLS Protocol Version 1.0
– Dierks, Allen
- 1999
|
|
165
|
IP Authentication Header
– Atkinson
- 1995
|
|
72
|
The Internet Key Exchange (IKE
– Harkins, Carrel
- 1998
|
|
69
|
Problem areas for the IP security protocols
– Bellovin
- 1996
|
|
49
|
P Encapsulating Security Payload (ESP
– Kent, Atkinson
- 1998
|
|
14
|
Performance enhancing proxies
– Border, Kojo, et al.
- 1994
|
|
5
|
IPSEC and the Internet
– Karir
- 1999
|
|
4
|
Transport-friendly ESP (or layer violations for fun and profit),” panel talk at the 1999
– Bellovin
- 1999
|
|
3
|
Satellite Communications in the Global Internet: Issues, Pitfalls, and Potential, Hughes Research Laboratories, INET'97
– Zhang, Lucia, et al.
- 1997
|
|
1
|
IPSEC: Friend or Foe. Panel discussion
– Nessett, Braden, et al.
- 1999
|