首页> 外文会议>International Workshop on Networked Appliances >APSSNMPAS a protocol for managing network appliances
【24h】

APSSNMPAS a protocol for managing network appliances

机译:APSSNMPA管理网络设备的协议

获取原文

摘要

Network appliances are getting more popular and common both in the household and in industry. As more items become network aware, the variety of items also increases drastically. This leads to more heterogeneous systems with different vendors providing different implementations. As network appliances' functionality is expanded, people develop a greater dependence on them and hence their status and the ease of controlling them become of paramount importance. It is also beneficial for the network appliances to be able to integrate with a large existing network for easier access. TCP/IP is a protocol with a large user base and is also the protocol of choice for the internet. It is also a well-tested and used protocol that is robust with many well developed hardware and even wireless access capabilities. This makes TCP/IP a suitable protocol to link network appliances or at least to link them to the outside. Simple Network Management Protocol (SNMP) [1, 2] is the network management protocol of choice for TCP/IP. By using the GetRequest PDU (Protocol Data Unit) of SNMP and proper MIB (Management Information Base) implementation of each networked appliance, the condition and various information of each item can be retrieved. Control of networked appliances can also be done via a SetRequest PDU on a MIB that will be polled to trigger an action on the item. There is even an Alarm PDU that a network appliance can send to indicate the completion of certain predefined tasks or emergency situation. Even if there are networked appliances where TCP/IP or SNMP cannot be suitably implemented, a proxy can easily be implemented to communicate with these items. The proxy can be implemented on the central networked appliance device or even a personal computer. However, the security mechanism for Simple Network Management Protocol version 1 and 2 (SNMPv1 and SNMPv2) are trivial [3] and therefore its potential to be a network management protocol have been limited to merely an observation/monitoring protocol. It is vital that the management protocol has sufficient security, as it might be disastrous for many networked appliances if exposed to unauthorized access such as alarms and temperature control. These security concerns were addressed by SNMPv3 (USM and VACM) [4, 5] but it is complex and difficult to implement on networked appliances and also on today's deployed systems. APSSNMP (Application Secure SNMP) [6] as proposed, is a simpler implementation that is easier and less costly to implement. It is also resistant to masquerade, modification, replay threats and also provide confidentiality. APSSNMP can be easily extended on the agent and provide backward compatibility with other devices implementing SNMP. APSSNMP will even provide logging capability indicating the last entity/user that instructed the network appliance to perform an action. Furthermore, the sensitive information in the database/MIB accessible via SNMP which would have been exposed is encrypted to maintain the confidentiality of the information (ie. whether the alarm is ON or not) to unauthorized observers. It is therefore a suitable choice to use a secure version of SNMP to provide a standardized management protocol for the various networked appliances that may come to the market.
机译:网络电器在家庭和工业中越来越受欢迎和共同。随着更多物品成为网络意识的,各种物品也急剧增加。这导致更多的异构系统,其中不同的供应商提供不同的实现。随着网络设备的功能扩大,人们对他们的依赖性更大,因此他们的状态和控制它们变得最重要的程度。对于网络设备来说,能够与大型现有网络集成以进行更容易访问,这也是有益的。 TCP / IP是一个具有大用户群的协议,也是互联网的选择协议。它也是一个经过良好测试和使用的协议,具有许多发达的硬件甚至无线访问能力的强大。这使得TCP / IP成为链接网络设备的合适协议,或者至少将它们链接到外部。简单的网络管理协议(SNMP)[1,2]是TCP / IP的选择的网络管理协议。通过使用SNMP的GetRequest PDU(协议数据单元)和每个联网设备的适当MIB(管理信息基础)实现,可以检索每个项目的条件和各种信息。还可以通过MIB上的SetRequest PDU对网络设备进行控制,该PDU将被轮询以触发在项目上的动作。甚至有一个警报PDU,网络设备可以发送以指示某些预定义任务或紧急情况的完成。即使存在不能适当地实现TCP / IP或SNMP的网络设备,也可以容易地实现代理以与这些项目通信。代理可以在中央网络设备设备甚至个人计算机上实现。然而,简单网络管理协议版本1和2(SNMPv1和SNMPv2)的安全机制是琐碎的[3],因此其成为网络管理协议的可能性仅限于仅是观察/监控协议。管理协议具有足够的安全性至关重要,因为如果暴露于未经授权的访问(如警报和温度控制),这可能对许多联网设备可能是灾难性的。 SNMPv3(USM和VACM)解决了这些安全问题[4,5],但它在网络设备上以及当今部署的系统上进行复杂且难以实现。 APSSNMP(Application Secure SNMP)[6]如提出的,是一种更简单的实现,实现更容易且成本更低。它也抵抗了化妆舞会,修改,重播威胁,也提供了保密性。 APSSNMP可以在代理上轻松扩展,并提供与实现SNMP的其他设备的向后兼容性。 APSSNMP甚至会提供指示指示网络设备执行动作的最后一个实体/用户的日志记录功能。此外,通过SNMP可访问的数据库/ MIB中的敏感信息被加密以维持信息的机密性(即,警报是否在未授权的观察者上)。因此,使用安全版本的SNMP是一个适当的选择,为可能出现市场的各种网络设备提供标准化的管理协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号