Title :
A new framework for secure network management
Author :
Hatefi, Farid G. ; Golshani, Forouzan
Author_Institution :
Dept. of Comput. Sci. & Eng., Arizona State Univ., Tempe, AZ, USA
Abstract :
We introduce a new protocol, SNMS (secure network management system) with four primary goals. First, it uses encryption to establish a secure channel between a network manager and a network agent. Second, it allows network management tasks to be performed from any station on the network. Third, it enables a manager to remotely add manageable objects to an agent. Finally, it makes a prototype along with a set of guidelines to make the transition from SNMP (simple network management protocol) to SNMS. The SNMS combines features from HTTP (hyper text transfer protocol), SSL (secure socket layer) security mechanism, and CGI (common gateway interface) programming techniques, and deals with the entire Web client/server paradigm. Network managers can securely monitor and control the network elements from any station on the network. Compared with SNMP, which does not provide any safety measures for exchanging information between a manager and an agent, the SNMS offers a high degree of security by encrypting all the traffic between the manager and an agent. The SNMS applies public key and private key encryption and decryption with a mixture of digital signature and two way authentication
Keywords :
Internet; computer network management; decoding; message authentication; protocols; public key cryptography; HTTP; SNMP; SNMS; Web client/server; common gateway interface programming; decryption; digital signature; encryption; hyper text transfer protocol; manageable objects; network agent; network elements control; network elements monitoring; network manager; private key encryption; public key encryption; secure channel; secure network management; secure network management system; secure socket layer security; simple network management protocol; two way authentication; Cryptography; Guidelines; Information security; Monitoring; Network servers; Protocols; Prototypes; Safety; Sockets; Web server;
Conference_Titel :
Computer Communications and Networks, 1997. Proceedings., Sixth International Conference on
Conference_Location :
Las Vegas, NV
Print_ISBN :
0-8186-8186-1
DOI :
10.1109/ICCCN.1997.623360