{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T08:47:34Z","timestamp":1750668454797,"version":"3.41.0"},"reference-count":41,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2020,12,6]],"date-time":"2020-12-06T00:00:00Z","timestamp":1607212800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2021,11,30]]},"abstract":"<jats:p>Networks play a central role in cyber-security: networks deliver security attacks, suffer from them, defend against them, and sometimes even cause them. This article is a concise tutorial on the large subject of networks and security, written for all those interested in networking, whether their specialty is security or not. To achieve this goal, we derive our focus and organization from two perspectives. The first perspective is that, although mechanisms for network security are extremely diverse, they are all instances of a few patterns. Consequently, after a pragmatic classification of security attacks, the main sections of the tutorial cover the four patterns for providing network security, of which the familiar three are cryptographic protocols, packet filtering, and dynamic resource allocation. Although cryptographic protocols hide the data contents of packets, they cannot hide packet headers. When users need to hide packet headers from adversaries, which may include the network from which they are receiving service, they must resort to the pattern of compound sessions and overlays. The second perspective comes from the observation that security mechanisms interact in important ways, with each other and with other aspects of networking, so each pattern includes a discussion of its interactions.<\/jats:p>","DOI":"10.1145\/3417988","type":"journal-article","created":{"date-parts":[[2020,12,6]],"date-time":"2020-12-06T22:23:20Z","timestamp":1607293400000},"page":"1-37","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Patterns and Interactions in Network Security"],"prefix":"10.1145","volume":"53","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-6568-2052","authenticated-orcid":false,"given":"Pamela","family":"Zave","sequence":"first","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jennifer","family":"Rexford","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,12,6]]},"reference":[{"volume-title":"NETSCOUT Arbor\u2019s 13th Annual Worldwide Infrastructure Security Report. https:\/\/2.zoppoz.workers.dev:443\/https\/pages.arbornetworks.com\/rs\/082-KNA-087\/images\/13th_Worldwide_Infrastructure_Security_Report.pdf","author":"Networks Arbor","key":"e_1_2_1_1_1","unstructured":"Arbor Networks . [n.d.]. NETSCOUT Arbor\u2019s 13th Annual Worldwide Infrastructure Security Report. https:\/\/2.zoppoz.workers.dev:443\/https\/pages.arbornetworks.com\/rs\/082-KNA-087\/images\/13th_Worldwide_Infrastructure_Security_Report.pdf . Arbor Networks. [n.d.]. NETSCOUT Arbor\u2019s 13th Annual Worldwide Infrastructure Security Report. https:\/\/2.zoppoz.workers.dev:443\/https\/pages.arbornetworks.com\/rs\/082-KNA-087\/images\/13th_Worldwide_Infrastructure_Security_Report.pdf."},{"key":"e_1_2_1_2_1","volume-title":"Cheriton","author":"Argyraki Katerina","year":"2005","unstructured":"Katerina Argyraki and David R . Cheriton . 2005 . Active Internet traffic filtering: Real-time response to denial-of-service attacks. In USENIX ATC. Katerina Argyraki and David R. Cheriton. 2005. Active Internet traffic filtering: Real-time response to denial-of-service attacks. In USENIX ATC."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3085591"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098822.3098834"},{"key":"e_1_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Ran Canetti. 2019. Universally Composable Security: A New Paradigm for Cryptographic Protocols. https:\/\/2.zoppoz.workers.dev:443\/https\/eprint.iacr.org\/2000\/067.pdf.  Ran Canetti. 2019. Universally Composable Security: A New Paradigm for Cryptographic Protocols. https:\/\/2.zoppoz.workers.dev:443\/https\/eprint.iacr.org\/2000\/067.pdf.","DOI":"10.1109\/SFCS.2001.959888"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/52324.52336"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.862650"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251375.1251396"},{"key":"e_1_2_1_9_1","unstructured":"Dyn [n.d.]. Dyn Analysis Summary of Friday October 21 Attack. https:\/\/2.zoppoz.workers.dev:443\/https\/dyn.com\/blog\/dyn-analysis-summary-of-friday-october-21-attack\/.  Dyn [n.d.]. Dyn Analysis Summary of Friday October 21 Attack. https:\/\/2.zoppoz.workers.dev:443\/https\/dyn.com\/blog\/dyn-analysis-summary-of-friday-october-21-attack\/."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/2789770.2789803"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382204"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488608.2488678"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2000.5340804"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10550-006-0084-z"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Handley Mark","year":"2001","unstructured":"Mark Handley , Vern Paxson , and Christian Kreibich . 2001 . Network intrusion detection: Evasion, traffic normalization, and end-to-end protocol semantics . In Proceedings of the 10th USENIX Security Symposium. Mark Handley, Vern Paxson, and Christian Kreibich. 2001. Network intrusion detection: Evasion, traffic normalization, and end-to-end protocol semantics. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046730"},{"key":"e_1_2_1_17_1","unstructured":"ITU. 1994. Information Technology\u2014Open Systems Interconnection\u2014Basic Reference Model: The Basic Model. ITU-T Recommendation X.200.  ITU. 1994. Information Technology\u2014Open Systems Interconnection\u2014Basic Reference Model: The Basic Model. ITU-T Recommendation X.200."},{"volume-title":"Proceedings of the USENIX Workshop on Free and Open Communications on the Internet. USENIX.","author":"Karlin Josh","key":"e_1_2_1_18_1","unstructured":"Josh Karlin , Daniel Ellard , Alden W. Jackson , Christine E. Jones , Greg Lauer , David P. Mankins , and W. Timothy Strayer . 2011. Decoy routing: Toward unblockable Internet communication . In Proceedings of the USENIX Workshop on Free and Open Communications on the Internet. USENIX. Josh Karlin, Daniel Ellard, Alden W. Jackson, Christine E. Jones, Greg Lauer, David P. Mankins, and W. Timothy Strayer. 2011. Decoy routing: Toward unblockable Internet communication. In Proceedings of the USENIX Workshop on Free and Open Communications on the Internet. USENIX."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/2482626.2482638"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23342"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2012.121112.00190"},{"volume-title":"Proceedings of ACM SIGCOMM.","author":"Adam","key":"e_1_2_1_22_1","unstructured":"Adam Langley et al. 2017. The QUIC transport protocol: Design and Internet-scale deployment . In Proceedings of ACM SIGCOMM. Adam Langley et al. 2017. The QUIC transport protocol: Design and Internet-scale deployment. In Proceedings of ACM SIGCOMM."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605438"},{"key":"e_1_2_1_24_1","unstructured":"Nuno P. Lopes Nikolaj Bjorner Patrice Godefroid Karthick Jayaraman and George Varghese. 2015. Checking beliefs in dynamic networks. In NSDI.  Nuno P. Lopes Nikolaj Bjorner Patrice Godefroid Karthick Jayaraman and George Varghese. 2015. Checking beliefs in dynamic networks. In NSDI."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/964725.633027"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/0743-1066(95)00095-X"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278534"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134074"},{"key":"e_1_2_1_29_1","volume-title":"HTTPS. In Proceedings of ACM CoNEXT.","author":"Naylor David","year":"2014","unstructured":"David Naylor , Alessandra Finamore , Ilias Leontiadis , Yan Grunenberger , Marco Mellia , Maurizio Munafo , Konstantina Papagiannaki , and Peter Steenkiste . 2014 . The cost of the \u2018S\u2019 in HTTPS. In Proceedings of ACM CoNEXT. David Naylor, Alessandra Finamore, Ilias Leontiadis, Yan Grunenberger, Marco Mellia, Maurizio Munafo, Konstantina Papagiannaki, and Peter Steenkiste. 2014. The cost of the \u2018S\u2019 in HTTPS. In Proceedings of ACM CoNEXT."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3143361.3143383"},{"key":"e_1_2_1_31_1","first-page":"4","article-title":"Anonymous connections and onion routing","volume":"16","author":"Reed Michael G.","year":"1998","unstructured":"Michael G. Reed , Paul F. Syverson , and David M. Goldschlag . 1998 . Anonymous connections and onion routing . IEEE JSAC 16 , 4 (May 1998), 482--494. Michael G. Reed, Paul F. Syverson, and David M. Goldschlag. 1998. Anonymous connections and onion routing. IEEE JSAC 16, 4 (May 1998), 482--494.","journal-title":"IEEE JSAC"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/347059.347560"},{"key":"e_1_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Y. Sheffer R. Holz and P. Saint-Andre. 2015. Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS). Internet Engineering Task Force Request for Comments 7457.  Y. Sheffer R. Holz and P. Saint-Andre. 2015. Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS). Internet Engineering Task Force Request for Comments 7457.","DOI":"10.17487\/rfc7457"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785956.2787502"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"e_1_2_1_36_1","volume-title":"Systematic classification of side-channel attacks: A case study for mobile devices","author":"Spreitzer Raphael","year":"2018","unstructured":"Raphael Spreitzer , Veelasha Moonsamy , Thomas Korak , and Stefan Mangard . 2018. Systematic classification of side-channel attacks: A case study for mobile devices . IEEE Communications Surveys 8 Tutorials 20, 1 ( 2018 ), 465--488. Raphael Spreitzer, Veelasha Moonsamy, Thomas Korak, and Stefan Mangard. 2018. Systematic classification of side-channel attacks: A case study for mobile devices. IEEE Communications Surveys 8 Tutorials 20, 1 (2018), 465--488."},{"key":"e_1_2_1_37_1","unstructured":"Janet Vertesi. [n.d.]. My Experiment Opting Out of Big Data Made Me Look Like a Criminal. https:\/\/2.zoppoz.workers.dev:443\/https\/time.com\/83200\/privacy-internet-big-data-opt-out.  Janet Vertesi. [n.d.]. My Experiment Opting Out of Big Data Made Me Look Like a Criminal. https:\/\/2.zoppoz.workers.dev:443\/https\/time.com\/83200\/privacy-internet-big-data-opt-out."},{"volume-title":"Proceedings of the USENIX Security Symposium.","author":"Wustrow Eric","key":"e_1_2_1_38_1","unstructured":"Eric Wustrow , Scott Wolchok , Ian Goldberg , and J. Alex Halderman . 2011. Telex: Anticensorship in the network infrastructure . In Proceedings of the USENIX Security Symposium. Eric Wustrow, Scott Wolchok, Ian Goldberg, and J. Alex Halderman. 2011. Telex: Anticensorship in the network infrastructure. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2003.1199330"},{"key":"e_1_2_1_40_1","first-page":"3","article-title":"The compositional architecture of the","volume":"62","author":"Zave Pamela","year":"2019","unstructured":"Pamela Zave and Jennifer Rexford . 2019 . The compositional architecture of the Internet. Commun. ACM 62 , 3 (March 2019), 78--87. Pamela Zave and Jennifer Rexford. 2019. The compositional architecture of the Internet. Commun. ACM 62, 3 (March 2019), 78--87.","journal-title":"Internet. Commun. ACM"},{"key":"e_1_2_1_41_1","volume-title":"Patterns and Interactions in Network Security. arXiv","author":"Zave Pamela","year":"1912","unstructured":"Pamela Zave and Jennifer Rexford . 2019. Patterns and Interactions in Network Security. arXiv 1912 .13371 [cs:NI]. Pamela Zave and Jennifer Rexford. 2019. Patterns and Interactions in Network Security. arXiv 1912.13371 [cs:NI]."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3417988","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3417988","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:15Z","timestamp":1750197675000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3417988"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,6]]},"references-count":41,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2021,11,30]]}},"alternative-id":["10.1145\/3417988"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3417988","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"type":"print","value":"0360-0300"},{"type":"electronic","value":"1557-7341"}],"subject":[],"published":{"date-parts":[[2020,12,6]]},"assertion":[{"value":"2020-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}