The lack of transparency for Internet communication prevents effective mitigation of today's security threats: i) Source addresses cannot be trusted and enable untraceable reflection attacks. ii) Malicious communication is opaque to all network entities, except for the receiver; and although ISPs are control points that can stop such attacks, effective detection and mitigation requires information that is available only at the end hosts. We propose TRIS, an architecture that bootstraps transparency for Internet communication. TRIS enables the definition of misbehavior according to the unique requirements of hosts, and then it constructs verifiable evidence of misbehavior. First, hosts express desired traffic properties for incoming traffic; a deviation from these properties signifies misbehavior. Second, ISPs construct verifiable evidence of misbehavior for the traffic they forward. If misbehavior is detected, it can then be proven to the ISPs of the communicating hosts. We implement our architecture on commodity hardware and demonstrate that verifiable proof of misbehavior introduces little overhead with respect to bandwidth and packet processing in the network: our prototype achieves line-rate performance for common packet sizes, saturating a 10 Gbps link with a single CPU core. In addition, we tackle incremental deployment issues and describe interoperability with today's Internet architecture.
In this chapter, we describe the header formats of SCION control and data packets. We start with the description of the generic SCION header, which consists of four parts: a common header, a forwarding path, an extensions chain, and a layer-4 protocol header.
In this chapter, we describe how ISDs are discovered and how they coordinate with each other, especially when a new ISD is created. The goal is for each ISD to have a list of all other ISDs — specifically, an identifier and a description for each ISD along with the roots of trust that enable authentication. An authority could create such a list and distribute it, but this would conflict with SCION’s goal that each ISD can operate independently and communicate with other ISDs without any globally trusted entity.
Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable.
This chapter describes the details of SCION configuration files. All SCION configuration files are represented in JSON [42] format.
This chapter presents Origin and Path Trace (OPT)—lightweight, scalable, and secure protocols for shared key setup, source authentication, and path validation. In-network source authentication and path validation are fundamental primitives for constructing higher-level security mechanisms such as DDoS mitigation, path compliance, packet attribution, or protection against flow redirection.
Adhering to the end-to-end principle even more than the current Internet yields highly available point-to-point communication.
The Internet has been successful beyond even the most optimistic expectations. It permeates and intertwines with almost all aspects of our society and economy. The success of the Internet has created a dependency on communication as many of the processes underpinning the foundations of modern society would grind to a halt should communication become unavailable. However, much to our dismay, the current state of safety and availability of the Internet is far from commensurate with its importance. Although we cannot conclusively determine what the impact of a 1-minute, 1-hour, 1-day, or 1-week outage of Internet connectivity on our society would be, anecdotal evidence indicates that even short outages have a profound negative impact on governmental, economic, and societal operations [11]. To make matters worse, the Internet has not been primarily designed for high availability in the face of malicious actions by adversaries. Recent patches to improve Internet security and availability have been constrained by the design of the current Internet architecture. A new Internet architecture should offer availability, security by design, provide incentives for deployment, and consider economic, political, and legal issues at the design stage. We believe addressing these issues requires a new cohesive architecture that provides one fundamental building block: highly available point-to-point communication, which other proposed future Internet architectures that provide content-centric [9, 15], extensibility-centric [14], or mobilitycentric [23] properties could build upon. This article describes SCION (Scalability, Control, and Isolation On Next-generation networks), an inter-domain network architecture designed to address these issues. We discuss SCION’s goals, design, and functionality, as well as the results of 5 years of research conducted since the initial publication [29].
The Internet, including user equipment, data transmission media, data centers, and access networks, requires a considerable amount of power, consuming nearly 1% of annual electricity production worldwide in 2010 [111]. Around 50 GW of power is consumed by network equipment, and this number is expected to double by 2020 [245]. Increased power consumption not only implies greater monetary cost, but also has an expanding environmental impact in the form of carbon footprint and pollution [96]. Reversing the trend is imperative and would pay off massively.
In this article, we address the problem of scaling authentication for naming, routing, and end-entity (EE) certification to a global environment in which authentication policies and users’ sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and EE certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose the Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities’ authentication information globally discoverable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures.
In this chapter, we describe the algorithm agility property provided by SCION, and the cryptographic algorithms used in the SCION architecture. Algorithm selection was motivated by two main requirements, security and efficiency, and was based on standards related to cryptography, recommendations, best practices, and performance evaluations [95, 190, 221, 224].
In this chapter, we discuss the authentication infrastructure of SCION, which enables verification of identities and assertions that data did indeed originate unchanged from the claimed entity. SCION offers built-in support for various types of authentication and various uses, and thus provides several infrastructures to support authentication.
Man-in-the-middle attacks in TLS due to compromised CAs have been mitigated by log-based PKI enhancements such as Certificate Transparency. However, these log-based schemes do not offer sufficient incentives to logs and monitors, and do not offer any actions that domains can take in response to CA misbehavior. We propose IKP, a blockchain-based PKI enhancement that offers automatic responses to CA misbehavior and incentives for those who help detect misbehavior. IKP’s decentralized nature and smart contract system allows open participation, offers incentives for vigilance over CAs, and enables financial recourse against misbehavior. We demonstrate through a game theoretic model and through an Ethereum prototype implementation that the incentives and increased deterrence offered by IKP are technically and economically viable.
We propose a demonstration of SCION, a future Internet Architecture designed for the 21st century. We demonstrate SCION's various rich features (including DDoS defense, native multipath communication, high-speed anonymous routing) and its ease of deployment.
Forwarding accountability mechanisms pinpoint the sending/forwarding properties of traffic to the entities that send and forward the traffic along a path. In this paper, we take flooding attacks as a use case and describe a proposal to hold senders accountable for the sending rates of their flows. Furthermore, we describe the corresponding challenges, potential solutions, and briefly present the literature in the area of forwarding accountability.
This paper proposes a Scalable Internet Bandwidth Reservation Architecture (SIBRA) as a new approach against DDoS attacks, which, until now, continue to be a menace on today's Internet.SIBRA provides scalable inter-domain resource allocations and botnet-size independence, an important property to realize why previous defense approaches are insufficient.Botnetsize independence enables two end hosts to set up communication regardless of the size of distributed botnets in any Autonomous System in the Internet.SIBRA thus ends the arms race between DDoS attackers and defenders.Furthermore, SIBRA is based on purely stateless operations for reservation renewal, flow monitoring, and policing, resulting in highly efficient router operation, which is demonstrated with a full implementation.Finally, SIBRA supports Dynamic Interdomain Leased Lines (DILLs), offering new business opportunities for ISPs.
Peter Stuckey合作论文数Faculty of Information Technology, Monash University1