Collaborative Research: NeTS—FIND: Privacy-Preserving Attribution and Provenence

Alex C. Snoeren, Tadayoshi Kohno, Stefan Savage, Amin M. Vahdat, Geoffrey M. Voelker · 2010

The Internet architecture was developed to support a number of key goals. Security was not among them. Indeed, in David Clark’s classic paper, “The Design Philosophy of the DARPA Internet Protocols, ” the word security is not used once. By any accounting, security mechanisms have been added to the Internet in a fashion both post hoc and ad hoc, with minimal accommodations from the surrounding communications framework. Inevitably, these mechanisms have provided only an approximation to the security properties motivating their creation and have frequently conflicted with the existing network architecture in which they operate. The network firewall represents a classic example of this tension. A firewall is expected to help enforce an access control policy on traffic traversing its links and yet is unable to make any strong statements about the sender of a piece of traffic or the import of the content it contains. Moreover, in enforcing crude controls, firewalls routinely violate the end-to-end properties of protocols that traverse them. We contend that many of these problems result from a mismatch between the level of abstraction provided by today’s network architecture and the level necessary to describe real security properties. Real-world security policies are invariably about “who ” and “what, ” while the Internet’s architecture answers “where” and “how. ” For example, Internet addresses describe topological endpoints that are inherently virtual. Due to hot spots, spoofing, route hijacking, etc., an IP address in a packet may have only a transient relationship

Read the paper · More papers on PaperTik