Browse > Article

Active Security Management on Active Networks  

이영석 (한국전자통신연구원)
Abstract
It has become more difficult to correspond an cyber attack quickly as a pattern of attack becomes various and complex. And, current security mechanisms just have passive defense functionalities. In this paper, we propose new network security architecture to respond various cyber attacks rapidly and to chase and isolate the attackers through cooperation between security zones. The proposed architecture make possible to deal effectively with cyber attacks such as IP spoofing or DDoS(Distributed Denial of Service) using active packet technology including a mobile sensor on active network. Active Security Management System based on proposed security architecture consists of active security node and active security server in a security zone, and is designed to have more active correspondent than that of existing mechanisms. We implemented these mechanisms in Linux routers and experimented on a testbed to verify realization possibility of Active Security Management System. The experimentation results are analyzed.
Keywords
Active Network; Active Security;
Citations & Related Records
연도 인용수 순위
  • Reference
1 /
[ NetGuard Inc. ] / GuardianPro V.5 Release Note V.5
2 Username/Password Authentication for SOCKS V5 /
[ M.Leech ] / IETF RFC1929
3 Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing /
[ P.Ferguson;D.Senie ] / IETF RFC2827
4 Active Network Intrusion Detection and Response(AN-IDR) /
[ Dan Sterne ] / Boeing and NAI Lab., DARPA FTM PI Meeting
5 액티브 네트워크 기반의 위조 IP 공격 대응 메커니즘 /
[ 이영석;방효찬;나중찬 ] / 한국정보과학회 춘계학술발표논문집
6 Cooperative Intrusion Traceback and Response Architecture(CITRA) /
[ Dan Schnackenberg(et al.) ] / DISCEX 2001
7 ESM 개발동향 /
[ 이영석;나중찬;손승원 ] / 한국전자통신연구원 주간기술동향
8 Security Architecture for the Internet Protocol /
[ S.Kent;R.Ackinson ] / IETF RFC2401
9 The Intrusion Detection Exchange Protocol (IDXP) /
[ B.Feinstein(et al.) ] / IETF draft-ietf-idwg-beep-idxp-07
10 액티브 기술을 이용한 DDoS 공격대응 /
[ 김현주;이수형;나중찬;손승원 ] / 한국정보과학회 추계학술발표논문집
11 IP Authentication Header /
[ S.Kent;R.Ackinson ] / IETF RFC2402
12 /
[ DARPA ITO ] / Dynamic Cooperating Boundary Controller(Project Introduction)
13 IP Encapsulating Security Payload /
[ S.Kent;R.Ackinson ] / IETF RFC2406
14 /
[] / ISO/IEC JTC1/SC27 WG1 Meeting
15 액티브 네트워크 기반 보안 기술 동향 /
[ 이수형;나중찬;손승원 ] / 한국전자통신연구원 주간기술동향