Network Security

profileSam Presto
hw3_tilton.docx

1. The End-to-End (E2E) security can be provisioned by implementing mechanisms and policies horizontally (Hosts-VLANS- BGP-BGP-VLANs-Hosts) and vertically (L1 through L7). As far as vertical implementation is concerned, we can put security mechanisms at various levels, as shown in Figure 1. We have covered Internet Protocol Security (IPSec) in Lecture 7, in which security mechanism is placed between Transport Control Protocol (TCP) and Internet Protocol (IP) layers.

Network Approach Transport Approach

( HTTP FTP SMTP TCP AH ESP IP ) ( HTTP FTP SMTP SSL/TLS TCP IP )

( SET PGP HTTP FTP SMTP TCP IP )Presentation Approach

Application Approach

( S−HTTP S/MINE TCP IP )

Figure 1: Placing Security Mechanisms

(a) Briefly describe (in your own words) the security mechanisms of the following protocols where we implement them at the:

i. Transport layer: Secure Sockets Layer (SSL)[3] and Transport Layer Security (TLS)[1].

ii. Application layer: Secure Hypertext Transfer Protocol (S-HTTP) [5], SMINE (Minimal Encapsulation (MINE)) [4, 2].

iii. Presentation layer: Secure Electronic Transaction (SET) and Pretty Good Privacy (PGP)[2].

(b) What is the difference between security mechanism and security policy?

(c) One has to strike a balance between network performance and security implementation. Which of the above security mechanisms puts more strain in performance as far as E2E security is concerned and why?

( Homework 3 ) ( Selected Topics: Network Security ) ( Due: Oct Nov 2 , 2014 )

( CS 6/79995 ) ( Oct Nov 3, 2014 ) ( Page 1 of 2 )

References

[1] T. Dierks and E. Rescorla. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246 (Proposed Standard), August 2008. Updated by RFCs 5746, 5878, 6176.

[2] M. Elkins, D. Del Torto, R. Levien, and T. Roessler. MIME Security with OpenPGP. RFC 3156 (Proposed Standard), August 2001.

[3] A. Freier, P. Karlton, and P. Kocher. The Secure Sockets Layer (SSL) Protocol Version 3.0. RFC 6101 (Historic), August 2011. [4] C. Perkins. Minimal Encapsulation within IP. RFC 2004 (Proposed Standard), October 1996.

[5] E. Rescorla and A. Schiffman. The Secure HyperText Transfer Protocol. RFC 2660 (Experimental), August 1999.