Service Cloaking and Authentication at Data Link Layer
Abstract
This paper discusses that there is significant benefit in providing stronger security at lower layers of the network stack for hosts connected to a network. It claims to reduce the attack vulnerability of a networked host by providing security mechanisms in a programmable Network Interface Card (NIC). Dynamic access control mechanisms are implemented in hardware to restrict access to the services provided, only to authenticated hosts. This reduces server vulnerability to various layer 2 attacks. Also the services will be immune to zero-day vulnerabilities due to the minimal code execution paths. To this end, it presents architecture and implementation details of a programmable network interface card equipped with these measures. It works alongside, and augments, existing security protocols making deployment practical.
- Publication:
-
arXiv e-prints
- Pub Date:
- April 2008
- DOI:
- 10.48550/arXiv.0804.3796
- arXiv:
- arXiv:0804.3796
- Bibcode:
- 2008arXiv0804.3796P
- Keywords:
-
- Computer Science - Networking and Internet Architecture;
- Computer Science - Cryptography and Security;
- C.2.0;
- C.2.5;
- D.4.6;
- K.4.4