摘要
1.引言
主动网络是一种可编程的分组交换网络,用户可以直接向网络节点插入用户定制的程序来配置或扩展网络的功能;也可以通过在报文分组中包含可执行的程序代码段,这些程序代码段由网络节点激活执行来修改或扩展网络的基础配置。主动网络的潜在优点是快速动态定制、配置网络中新的服务,提高网络的性能,使网络系统更具有灵活性、可扩展性[1,2]。主动网络通过提供通用的网络可编程接口,允许几乎所有的网络用户按各自的应用要求针对网络节点(路由器)、甚至直接针对报文进行编程并嵌入可执行的代码。
Active Networks offer the ability to program the network on per-router, per-user or even per-packet basis,and promise greater flexibility than current networks. Unfortunately,this added pro-grammability compromises the security of the system by allowing a wider range of potential attack. The active network will not only concern with possible damage to user data and end node,but also consider possible damage as the active packet moves into each node and EE. So enforcing protections at end nodes only is not sufficient for active networks. Securing an active network means that protection mechanisms must move into each node and each EE. Protecting the network as a whole is only possible by building a common protection mechanism into the design of individual nodes and EEs. In this paper,we mainly discuss the security mechanism and techniques how to protect the active network,the problem domain is divided into two particular :protecting active nodes from malicious active code;and protecting active code from malicious active nodes.Based on the study,a security model protecting active network nodes is presented.
出处
《计算机科学》
CSCD
北大核心
2001年第3期46-49,共4页
Computer Science
基金
国家自然科学基金