• Documents
  • Authors
  • Tables
  • Other Seers ▼
    RefSeer AckSeer CollabSeer SeerSeer
  • Log in
  • Sign up
  • MetaCart

CiteSeerX logo

Advanced Search Include Citations
Advanced Search Include Citations | Disambiguate

A System for Authenticated Policy-Compliant Routing (2004)

Cached

  • Download as a PDF

Download Links

  • [www.cs.ucsd.edu]
  • [www.cs.princeton.edu]
  • [www.cse.ucsd.edu]
  • [www.sigcomm.org]
  • [www.cs.princeton.edu:80]
  • [www.acm.org]
  • [acm.org]
  • [www.cs.ucsd.edu]
  • [www.cs.umd.edu]

  • Other Repositories/Bibliography

  • DBLP
  • Save to List
  • Add to Collection
  • Correct Errors
  • Monitor Changes
by Barath Raghavan , Alex C. Snoeren
Citations:46 - 5 self
  • Summary
  • Active Bibliography
  • Co-citation
  • Clustered Documents
  • Version History

BibTeX

@MISC{Raghavan04asystem,
    author = {Barath Raghavan and Alex C. Snoeren},
    title = {A System for Authenticated Policy-Compliant Routing},
    year = {2004}
}

Years of Citing Articles

Bookmark

citeulike Connotea Bibsonomy Del.icio.us Digg Reddit

OpenURL

 

Abstract

Internet end users and ISPs alike have little control over how packets are routed outside of their own AS, restricting their ability to achieve levels of performance, reliability, and utility that might otherwise be attained. While researchers have proposed a number of source-routing techniques to combat this limitation, there has thus far been no way for independent ASes to ensure that such traffic does not circumvent local traffic policies, nor to accurately determine the correct party to charge for forwarding the traffic. We present Platypus, an authenticated source routing system built around the concept of network capabilities. Network capabilities allow for accountable, fine-grained path selection by cryptographically attesting to policy compliance at each hop along a source route. Capabilities can be composed to construct routes through multiple ASes and can be delegated to third parties. Platypus caters to the needs of both end users and ISPs: users gain the ability to pool their resources and select routes other than the default, while ISPs maintain control over where, when, and whose packets traverse their networks. We describe how Platypus can be used to address several well-known issues in wide-area routing at both the edge and the core, and evaluate its performance, security, and interactions with existing protocols. Our results show that incremental deployment of Platypus can achieve immediate gains.

Citations

1134 Security architecture for the internet protocol - Kent, Atkinson - 1998
854 Resilient overlay networks - Andersen, Balakrishnan, et al. - 2001
488 Measuring ISP topologies with Rocketfuel - Spring, Mahajan, et al. - 2002
481 Multiprotocol Label Switching Architecture", RFC 3031 - Rosen, Viswanathan, et al. - 2001
294 Delayed Internet Routing Convergence - Labovitz, Ahuja, et al. - 2001
285 Internet indirection infrastructure - STOICA, ADKINS, et al.
278 HMAC: Keyed-Hashing for Message Authentication - Krawczyk, Bellare, et al.
234 T.: Understanding BGP misconfigurations - Mahajan, Wetherall, et al.
234 The end-to-end effects of internet path selection - Savage, Collins, et al. - 1999
176 Trajectory sampling for direct traffic observation - Duffield, Grossglauser - 2001
168 Tussle in Cyberspace: Defining Tomorrow’s Internet - Clark, Wroclawski - 2002
119 Routing underlay for overlay networks - Nakao, Peterson, et al. - 2003
105 On selfish routing in Internet-like environments - Qiu, Yang, et al. - 2003
99 Mayday: distributed filtering for Internet services - Andersen - 2003
96 P.: UMAC: Fast and secure message authentication - Black, Halevi, et al. - 1999
95 Quantifying the causes of path inflation - Spring, Mahajan, et al. - 2003
91 NIRA: A new Internet routing architecture - Yang - 2003
89 Preventing Internet Denial-of-Service with Capabilities - Anderson, Roscoe, et al. - 2004
76 User-level Internet path diagnosis - Mahajan, Spring, et al. - 2003
56 Commentary on inter-domain routing - Huston - 2001
49 The nimrod routing architecture - Castineyra, Chiappa, et al. - 1996
48 Space-Code Bloom Filter for Efficient Per-Flow Traffic Measurement - Kumar, Xu, et al.
46 A block-cipher mode of operation for parallelizable message authentication - Black, Rogaway - 2002
43 OPCA: Robust interdomain policy routing and traffic control - Agarwal, Chuah, et al. - 2003
39 Feedback based routing - Zhu, Gritter, et al.
32 Policy routing in internet protocols - Clark - 1989
32 VISA protocols for controlling inter-organizational datagram flow - Estrin, Mogul, et al. - 1989
30 BANANAS: An evolutionary framework for explicit and multipath routing in the Internet - Kaur, Kalyanaraman, et al. - 2003
29 Internet service providers and peering - Norton - 2000
26 LIRA: An Approach for Service Differentiation in the Internet - Stoica, Zhang - 1998
19 Source Demand Routing: Packet format and forwarding specification (version 1). Internet Draft - Estrin, Zappala, et al. - 1995
19 An inherent bottleneck in distributed counting - WATTENHOFER, WIDMAYER - 1997
14 On convergence of k-means and partitions with minimum average variance - MacQueen - 1965
13 Decoupling Policy from Mechanism in Internet Routing - Snoeren, Raghavan - 2003
12 Thekkath. Block-Level Security for Network-Attached Disks - Aguilera, Ji, et al. - 2003
10 Security issues in policy routing - Estrin, Tsudik - 1989
7 A brief history of ntp time: memoirs of an internet timekeeper - Mills - 2003
1 A record 2.3 million add broadband in first quarter of 2004 - Group - 2004
1 NITROX II: A family of in-line security processors - Sanzone, Katz, et al. - 2003
The National Science Foundation
  • About CiteSeerX
  • Submit Documents
  • Privacy Policy
  • Help
  • Data
  • Source
  • Contact Us

Developed at and hosted by The College of Information Sciences and Technology

© 2007-2010 The Pennsylvania State University