SECURITY ISSUES OF THE DYNAMIC PROXY FRAMEWORK

Authors

  • Choong Khong Neng Department of Computer and Communication, Faculty of Engineering, University Putra Malaysia,
  • Borhanuddin Mohd Ali Department of Computer and Communication, Faculty of Engineering, University Putra Malaysia
  • Veeraraghavan Prakash Department of Computer and Communication, Faculty of Engineering, University Putra Malaysia
  • Elok Robert Tee Department of Communication Technology and Networking, Faculty of Computer Science University Putra Malaysia
  • Yee Yoke Chek Motorola Multimedia Sdn BhdGlobal Software Group, 16th Floor Menara Luxor, 6B Jalan Persiaran Tropicana

Keywords:

Chek Proxy Framework;, CPF,, application level active network,, proxy security,, agent security,, fingerprint,, watermarking,, layered coding

Abstract

The security issues of a proxy-based service creation and content delivery framework called the Chek Proxy Framework (CPF) was dissussed. CPF is an application level approach that provokes the use of client machine to host at runtime, an intermediate object called the Dynamic Application Proxy Server (DAPS) to offload both the central server and the network backbone. However, introducing DAPS on the client machine to provide intermediary active services breaks the end-to-end nature of the communication, and thus triggers additional security breaches. These include the threat of executing malicious DAPS, the lost of data integrity and illegal redistribution of contents. A security framework to tackle these security breaches was presented, with an objective to derive a secure CPF hand-shaking setup protocol, based on analysis conducted on a video broadcasting system.

References

Baugher, M., Blom, R., Carrara, E., McGrew, D., Naslund, M., Norrman, K. and Oran,D. (2001). The secure real time transport protocol. IETF draft.

Bender, W., Gruhl, D., Morimoto, N. and Lu, A.(1996). Techniques for data hiding. IBMSystems Journal. 35(3 & 4):313-336.

Blaze, M., Bleumer, G. and Strauss, M. (1998).Protocol divertibility and atomic proxy cryptography. Proc. Eurocrypt, and Lecture Notes in Computer Science 1403.p. 127-144.

Brown, I. (2001). End-to-end security in active networks, PhD. thesis. Computer Science. University of London.

Canetti, R. (1997). Deniable encryption. Proc. of Advances in Cryptology (CRYPTO), and Lecture Notes in Computer Science 1294. Springer-Verlag. p. 90-104.

Choong, K.N., Mohd, A, B., Prakash, V., Tee, E.R., Yee, Y.C. (2002). The framework of a dynamic proxy system. Suranaree Journal of Science and Technology. 10(1): 7-18.

Coulouris, G., Dollimore, J. and Kindberg, T. (2001). Distributed systems: Concepts and design. 3rd Edition. Addison-Wesley.

Dierks, T. and Allen, C. (1999). The TLS Protocol Version 1.0. RFC 2246.

Fahmi, H., Latif, M., Sedigh-Ali, S., Ghafoor, A., Liu, P. and Hsu, L. (2001). Proxy servers for scalable interactive video support. IEEE Computer. 34(9):54-60.

Fankhauser, G., Dasen, M., Weiler, N., Plattner, B. and Stiller, B. (1998). The WaveVideoSystem and network architecture: Design and implementation. TIK technical report No. 44. ETH, Zurich.

Gennaro, R. and Rohatgi, P. (1997). How to sign digital streams. Proc. of Advances in Cryptology (CRYPTO), and Lecture Notes in Computer Science 1294. Springer-Verlag. p. 180-197.

Ghost, A., Fry, M. and Maclarty, G. (2001). An infrastructure for application level active networking. Elsevier Computer Publication. Networks. 36(1):5-20.

Golle, P. and Modadugu, N. (2001). Authenticating streamed data in the presence of random packet loss, Extended Abstract. Available from: http:// www.isoc.org/isoc/ conferences/ ndss/01/ 2001/papers/golle.pdf

Hicks, M.W., Kakkar, P., Moore, J.T., Gunter, C.A. and Nettles, S. (1998). PLAN: A packet language for active networks. Proc. of the 3rd ACM SIGPLAN International Conference on Functional Programming (ICFP). Baltimore, Maryland. USA. p. 86-93.

Josang, A. (1999). Trust-based decision making for electronic transactions. Proc. of the 4th Nordic Workshop on Secure IT Systems (NORDSEC). Stockholm, Sweden.

Musmann, H.G. (1995). A layered coding scheme for very low bit rate video coding, Signal Processing: Image Communication. 7:267-278.

Oppliger, R. (1997). Internet security: Firewalls and beyond. Communications of the ACM. 40(5):92-102.

Portmann, M. and Seneviratne, A. (2000). The problem of end-to-end security for proxybased systems. Proc. of Protocols for Multimedia Systems (PROMS), October 22-25. Available at: http://mobqos. ee.unsw.edu.au/mobqos/Papers/ID15_ proms2000.pdf. Access date: Jan 2002.

Smith, J.M., Calvert, K., Murphy, S., Orman, H.K. and Peterson, L.L. (1999). Activating- networks: A progress report. IEEE5 Computer. 32(4):32-41.

Thayer, R., Doraswamy, N. and Glenn, R. (1998). IP Security Document Roadmap. RFC 2411.

Wolfgang, R.B. and Delp, E.J. (1997). A watermarking technique for digital imagery: Further studies. Proc. of the IEEE International Conference on Imaging, Systems and Technology. Las Vegas, NV, USA. p. 279-287.

Yatin, D.C. (2000). Scattercast: An architecture for Internet broadcast distribution as an infrastructure service. Ph.D. thesis, Computer Science Division. University of California. Berkeley.

Downloads

Published

2026-08-27

How to Cite

Khong Neng, C., Mohd Ali, B., Prakash, V., Robert Tee, E., & Yoke Chek, Y. (2026). SECURITY ISSUES OF THE DYNAMIC PROXY FRAMEWORK. Suranaree Journal of Science and Technology, 11(1), 17–29. retrieved from https://ph04.tci-thaijo.org/index.php/SUJST/article/view/13117

Issue

Section

Research Article