Internet security standards

Stephen Kent · StandardView · 1994

n Security is a topic of great interest as the Internet transitions from the R & 0 environment to the commercial sector and the home.This afiicle traces the evolution of security standards in the Internet and previews work now underway.he Internet protocol suite (e.g., IP, TCP) has been criticized as having been designed with no thought of security.People point to the ease with which IP addresses can be spoofed; the lack of security for name and address mappings provided by the Domain Name System (DNS); the lack of accounting facilities; the difficulty of operating some protocols across "firewall gateways," and similar characteristics, as evidence of failure to anticipate security requirements.These observations, while generally true, do not fully support the criticism.For example, IP was designed to operate over lower network layer protocols such as X.25, and it was assumed that these lower network layer protocols would enforce network-specific charging policies The construction of networks from IP routers without the use of a lower network layer protocol was not part of the IP model, which also explains the lack of congestion control facilities in IP.Contrary to popular belief, IP was designed with a security model in mind [Kent 1993al.The model assumes the use of end-to-end cryptographic protection at the network layer for most user-oriented security services and the use of link layer cryptography for trafftc-flow confidentiality.TCP/IP was developed initially for use by the U.S. Department of Defense (DOD).In the DOD environment, the threats are such that the only accepted means of providing high-quality security in a large, geographically distributed network is through the application of cryptography.Appropriately designed, IP-layer cryptographic devices offer (connectionless) confidentiality and integrity, data-origin authentication, and enforcement of identity and rule-based access control through automated key distribution.Uniform use of such cryptographic security technology addresses many of the concerns cited above.Prototype devices implementing these services in the TCP/IP environment were developed, tested, and deployed on a limited basis in the late 1970s as part of DoD-sponsored R&D programs--well before security became a common concern for many Internet users, before the term "information superhighway" became a buzzword, and before the advent of the Internet standards process.

Read the paper · More papers on PaperTik