Date: 2007-02-20 09:06 pm (UTC)
From: (Anonymous)
There are many reasons to prefer transport-layer to network-layer security. As you have mentioned, network-layer solutions need to be implemented in the operating system kernel making them particularly inconvenient to deploy. Also, IPsec (which for all practical purposes is the only network-layer protocol we have) has been widely criticized (http://www.schneier.com/paper-ipsec.html) for being exceptionally complex and this fact hinders in depth security evaluations. However, I think that the most important argument against network-layer security is that it violates basic networking stack architecture principles. When you are doing security management at the network layer it usually means that you lose all the reliability and reassembly features provided by the transport layer. To be able to make security decisions (like authentication, authorization, etc.) you need to re-implement many TCP features that allow you to assemble network packets at the network layer, thus breaking the purpose behind the separation of functionality into layers.

--
Patroklos Argyroudis
http://ntrg.cs.tcd.ie/~argp/
(will be screened)
(will be screened if not validated)
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

Profile

ciphergoth: (Default)
Paul Crowley

January 2025

S M T W T F S
   1234
5678 91011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Dec. 24th, 2025 07:40 pm
Powered by Dreamwidth Studios