MarketNet: Market-Based Protection of Network Systems and Services - An Application to SNMP Protection

نویسندگان

  • Apostolos Dailianas
  • Yechiam Yemini
  • Danilo Florissi
  • Hao Huang
چکیده

This research is sponsored in part by the USAF, Air Force Materiel Command, under contract F30602-97-1-0252, "MarketNet: A Survivable, Market-based Architecture for Large-scale Information Systems", and in part by the New York Science and Technology Foundation, subcontract with Polytechnic University. The views and conclusions contained in this document are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied of the Defense Advanced Research Projects Agency (DARPA), the Air Force, or the U.S. Government. Abstract Current networks allocate attack and protection powers asymmetrically. Attackers can exercise virtually unlimited power to attempt to compromise systems and evade detection and accountability, while the owners of these systems are mostly limited to developing passive protections and keeping up with new attack techniques. This paper describes novel protection technologies, developed by the MarketNet project at Columbia University, that shift power from attackers to defenders, giving the defenders control over the exposure to attacks and over detectability and accountability of attackers. MarketNet uses market-based techniques to regulate access to resources. Access to a resource must be paid-for with currency issued by its domain. Domains can control the power of attackers by limiting the budgets allocated to them, and control the exposure of resources by setting their prices, effectively providing a quantifiable access control mechanism. Domains can monitor currency flows and use uniform resource-independent statistical algorithms to correlate and detect access anomalies indicating potential attacks. Currency is marked with unique identifiers that permit domains to establish verifiable accountability in accessing their resources. Domains control and fine tune their exposure to attacks; adjust this exposure in response to emerging risks; detect intrusion attacks through automated, uniform statistical analysis of currency flows; and establish coordinated response to attacks. MarketNet mechanisms unify and kernelize global information systems protection by containing all protection logic in a small core of software components. The paper presents the architecture and operation of MarketNet along with the design and implementation of main architectural components. The paper illustrates the application of MarketNet to the protection of the Simple Network Management Protocol (SNMP) and compares it with the security features offered by SNMPv3.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Overview on Microgrid Concept with Special Focus on Islanding Protection Issues

Subscriber service is not feasible in the construction of large-scale traditional networks with the aim of providing more services. The high distance between production and consumption requires the definition of a transmission network as a challenging intermediary. The cost of transmission network and the risk associated with it cannot be ignored at all. The idea of a microgrid, which began wit...

متن کامل

Power Differential based Wide Area Protection

Current differential based wide area protection (WAP) has recently been proposed as a technique to increase the reliability of protection systems. It increases system stability and can prevent large contingencies such as cascading outages and blackouts. This paper describes how power differential protection (PDP) can be used within a WAP and shows that the algorithm operates correctly for a...

متن کامل

Adaptive Protection Based on Intelligent Distribution Networks with the Help of Network Factorization in the Presence of Distributed Generation Resources

Factorizing a system is one of the best ways to make a system intelligent. Factorizing the protection system, providing the right connecting agents, and transmitting the information faster and more reliably can improve the performance of a protection system and maintain system reliability against distributed generation resources. This study presents a new method for coordinating network protect...

متن کامل

MarketNet: protecting access to information systems through financial market controls

This paper describes novel market-based technologies that uniquely establish quantifiable and adjustable limits on the power of attackers, enable verifiable accountability for malicious attacks, and admit systematic and uniform monitoring and detection of attacks. These technologies, incorporated in the MarketNet system, establish a financial economy to regulate the trade and use of access righ...

متن کامل

RFC 5953 TLS Transport Model for SNMP August

This document describes a Transport Model for the Simple Network Management Protocol (SNMP), that uses either the Transport Layer Security protocol or the Datagram Transport Layer Security (DTLS) protocol. The TLS and DTLS protocols provide authentication and privacy services for SNMP applications. This document describes how the TLS Transport Model (TLSTM) implements the needed features of a S...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000