A security model for dynamic adaptive traffic masking

Brenda Timmerman · 1997

As missiork critical corrkrrkzkrkiculion inci-cases ark operk in-ternetworks, there is a growing need for erkd-to-end protec-fiork frorrz trujfic unu&sis. #kzs additiolkal protection cnrk bt expensive and detrimental to performunce when padding is used to mask trufli(: putterfks. ‘Trakfic rrkusking policies that arc responsrve to system servzce requirements can z’rnprove perjorrnance and lower cost. However, udaptive tru$ic masking has to balance perjorrnurkce requirements with system protection requirements und thus address the information leaks that result from adaptations. This paper defines u ‘new security model for adaptzve trafJc masking that satisfies system requirements for protection, efjiciency, and perfor-mance. It preserkts secure dynamic aduptive trafic masking (S-DATM) techniques, defines a security model for dynamic adaptive trajJic maskirlg (SMD), and presents an example of the model upplied to a network protocol. Mechanisms that utilize S-DATM techniques can integrate into existing security protocols to provide end-to-end protection that is scalable to anternetworks. S-DATM detects and limits information leuks cuused by dynamic adaptation. SMD is based on a probabilistic state machine formulation. It allows secure tradt>-ojJs bet,ween protection und performance as well (13 SpeCkfykrlg t/kc SccUrkty reqUiWlnerkt.5 for S-DATM medka-rkksms.

Read the paper · More papers on PaperTik