Hicks, MichaelKeromytis, Angelos DSmith, Jonathan M2023-05-222023-05-222003-08-012004-11-12https://repository.upenn.edu/handle/20.500.14332/6413Active networks, being programmable, promise greater flexibility than current networks. Programmability, however, may introduce safety and security risks. This correspondence describes the design and implementation of a security architecture for the active network PLANet [1]. Security is obtained with a two-level architecture that combines a functionally restricted packet language, PLAN [2], with an environment of general-purpose service routines governed by trust management [3]. In particular, a technique is used which expands or contracts a packet's service environment based on its level of privilege, termed namespace-based security. The design and implementation of an active-network firewall and virtual private network is used as an application of the security architecture. Measurements of the system show that the addition of the firewall imposes an approximately 34% latency overhead and as little as a 6.7% space overhead to incoming packets.Active firewallactive networksactive packetsPLANprogramming languagessecurityA Secure PLANArticle