Stephen T. Kent

dblp:26/6838 · DBLP profile ↗
← Back
15ranked-venue papers
8as first author
0since 2021 · last 2002
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 4 first-authorSecurity and privacy · 6 · 4 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
9 papers
Network security · 51% Cryptographic protocols and secure computation · 25% Authentication and access control · 17%
Computer networks
5 papers
Routing and switching · 93% Cellular and mobile networks · 7%

Topics — the 17 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Routing and switching › inter-domain routing
BGP
0.122000
Secure Border Gateway Protocol (S-BGP) · IEEE J. Sel. Areas Commun. 2000
Secure Border Gateway Protocol (S-BGP) - Real World Performance and Deployment Issues · NDSS 2000
Cryptographic protocols and secure computation › key management
public key infrastructure
0.122002
Rethinking PKI: What's Trust Got to Do with It? · EUROCRYPT 2002
A Public-Key Based Secure Mobile IP · MobiCom 1997
Network security
IP traceback
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Network security
traffic analysis
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Authentication and access control › trust management
trust models
0.012002
Rethinking PKI: What's Trust Got to Do with It? · EUROCRYPT 2002
Routing and switching
inter-domain routing
0.012000
Secure Border Gateway Protocol (S-BGP) · IEEE J. Sel. Areas Commun. 2000
Routing and switching › inter-domain routing
inter-domain routing security
0.012000
Secure Border Gateway Protocol (S-BGP) - Real World Performance and Deployment Issues · NDSS 2000
Network security
routing security
0.012000
Secure Border Gateway Protocol (S-BGP) · IEEE J. Sel. Areas Commun. 2000
Network security › attack resilience › attack mitigation
denial-of-service defense
0.011997
Securing the Nimrod Routing Architecture · NDSS 1997
Cryptographic protocols and secure computation
key management
0.011997
A Public-Key Based Secure Mobile IP · MobiCom 1997
Routing and switching
packet forwarding
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Authentication and access control
certificate management
0.012002
Rethinking PKI: What's Trust Got to Do with It? · EUROCRYPT 2002
Cryptographic protocols and secure computation
internet security protocols
0.011999
Network Security: Then and Now, or, 20 Years in 10 Minutes · S&P 1999
Cellular and mobile networks › mobility management
Mobile IP
0.011997
A Public-Key Based Secure Mobile IP · MobiCom 1997
Cellular and mobile networks
mobility management
0.011997
A Public-Key Based Secure Mobile IP · MobiCom 1997
Cryptographic protocols and secure computation
key exchange
0.011981
Security Requirements and Protocols for a Broadcast Scenario · IEEE Trans. Commun. 1981
Network security › secure communication
secure communication protocol
0.011977
Encryption-based protection for interactive user/computer communication · SIGCOMM 1977

Methods — techniques the papers use, named apart from their topics

simulation · 0.1hashing · 0.1performance analysis · 0.1x.509 · 0.0shared secret establishment · 0.0sequence integrity mechanisms · 0.0cross certification · 0.0IPsec · 0.0public-key ciphers · 0.0conventional ciphers · 0.0
YearPublicationVenuePosition
2002 Rethinking PKI: What's Trust Got to Do with It?
Stephen T. Kent
EUROCRYPT1
2002 Single-packet IP traceback
abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
Alex C. Snoeren, Craig Partridge, Christine E. Jones, Fabrice Tchakountio, Beverly Schwartz, Stephen T. Kent, W. Timothy Strayer
IEEE/ACM Trans. Netw.7
2000 Secure Border Gateway Protocol (S-BGP) - Real World Performance and Deployment Issues
Stephen T. Kent, Charles Lynn, Joanne Mikkelson, Karen Seo
NDSS1
2000 Secure Border Gateway Protocol (S-BGP)
abstract
The Border Gateway Protocol (BGP), which is used to distribute routing information between autonomous systems (ASes), is a critical component of the Internet's routing infrastructure. It is highly vulnerable to a variety of malicious attacks, due to the lack of a secure means of verifying the authenticity and legitimacy of BGP control traffic. This paper describes a secure, scalable, deployable architecture (S-BGP) for an authorization and authentication system that addresses most of the security problems associated with BGP. The paper discusses the vulnerabilities and security requirements associated with BGP, describes the S-BGP countermeasures, and explains how they address these vulnerabilities and requirements. In addition, this paper provides a comparison of this architecture to other approaches that have been proposed, analyzes the performance implications of the proposed countermeasures, and addresses operational issues.
Stephen T. Kent, Charles Lynn, Karen Seo
IEEE J. Sel. Areas Commun.1
1999 R&D Challenges: Notes from the "Trust in Cyberspace" Report
Stephen T. Kent
NDSS1
1999 Network Security: Then and Now, or, 20 Years in 10 Minutes
abstract
Summary form only given. The history of network security is outlined by looking at technology in 1979 and comparing it with that of 1999. The following areas are included: crypto based net security; access control and authentication; and security protocols.
Stephen T. Kent
S&P1
1999 A public-key based secure Mobile IP
John Zao, Stephen T. Kent, Joshua Gahm, Gregory D. Troxel, Matthew Condell, Pam Helinek, Nina Yuan, Isidro Castiñeyra
Wirel. Networks2
1997 A Public-Key Based Secure Mobile IP
abstract
The need of scaleable key management support for Mobile IP, especially the route‐optimized Mobile IP, is well known. In this paper, we present the design and the implementation of a public key management system that can be used with IETF basic and route optimized Mobile IP. The system, known as the Mobile IP Security (MoIPS) system, was built upon a DNS based X.509 Public Key Infrastructure and the innovation in cross certification and zero‐message key generation. The system can supply cryptographic keys for authenticating Mobile IPv.4 location management messages and establishing IPSec tunnels for Mobile IP redirected packets. It can also be used to augment firewall traversal of Mobile IP datagrams. A FreeBSD UNIX implementation of the MoIPS prototype is available for non‐commercial uses.
John Zao, Stephen T. Kent, Joshua Gahm, Gregory D. Troxel, Matthew Condell, Pam Helinek, Nina Yuan, Isidro Castiñeyra
MobiCom2
1997 Securing the Nimrod Routing Architecture
abstract
This paper describes the work undertaken to secure Nimrod, a complex and sophisticated routing system that unifies interior and exterior routing functions. The focus of this work is countering attacks that would degrade or deny service to network subscribers. The work began with an analysis of security requirements for Nimrod, based on a hybrid approach that refines top-down requirements generation with an understanding of attack scenarios and the capabilities and limitations of countermeasures. The countermeasures selected for use here include several newly developed sequence integrity mechanisms, plus a protocol for shared secret establishment. A novel aspect of this work is the protection of subscriber traffic in support of the overall communication availability security goal.
Karen E. Sirois, Stephen T. Kent
NDSS2
1985 Security mechanisms in a transport layer protocol
Victor L. Voydock, Stephen T. Kent
Comput. Secur.2
1984 Security Mechanisms in a Transport Layer Protocol
Victor L. Voydock, Stephen T. Kent
Comput. Networks2
1981 Security Requirements and Protocols for a Broadcast Scenario
abstract
Previous work (e.g., [1], [2]) has characterized communication security requirements in connection-oriented (virtual circuit) environments supporting applications such as interactive communication and file transfer. This work has developed protocols to achieve these requirements using conventional ciphers (CC's) such as the NBS data encryption standard (DES) [3]. More recently, several authors [4]-[6] have analyzed key distribution protocols for such environments based on CC's and on public-key ciphers (PKC's) such as the RSA algorithm [7], noting similarities in form, function, and vulnerability. Advances in satellite and packet radio technology [8], [9] and the development of high-speed, local area networks [10] have stimulated interest in broadcast protocols for various applications. This article examines security requirements for a simple broadcast scenario characteristic of some of these applications and develops protocols for achieving these requirements. Two sets of protocols, one based on CC's and the other based on PKC's, are developed and analyzed in terms of functionality and performance.
Stephen T. Kent
IEEE Trans. Commun.1
1981 Correction to "Security Requirements and Protocols for a Broadcast Scenario"
Stephen T. Kent
IEEE Trans. Commun.1
1981 Correction to the Special Section on Computer Network Security of the June 1981 Issue
Miles E. Smid, Richard E. Lennon, Stephen M. Matyas, Carl H. Meyer, Stephen T. Kent
IEEE Trans. Commun.5
1977 Encryption-based protection for interactive user/computer communication
abstract
This paper develops a virtual connection model, complete with intruder, for interactive terminal-host communication and presents a set of protection goals that characterize the security that can be provided for a physically unsecured connection. Fundamental requirements for protocols that achieve these goals and the role of encryption in the design of such protocols are examined. Functional and security constraints on positioning of protection protocols in a communication system and the impact of positioning on the design of secure operating systems are discussed.
Stephen T. Kent
SIGCOMM1