Enabling Secure and Dynamic Deep Packet Inspection in Outsourced Middleboxes

计算机科学 深包检验 网络数据包 计算机网络 计算机安全
作者
Yu Guo,Cong Wang,Xiaohua Jia
标识
DOI:10.1145/3201595.3201601
摘要

Outsourced middlebox services have been a natural trend in modern enterprise networks to handle advanced traffic processing such as deep packet inspection, traffic classification, and load balancing. However, traffic redirection to outsourced middleboxes raises new security and privacy concerns, as this service model gives cloud providers full access to all the enterprise's traffic flows and proprietary middlebox rules. To ease these concerns, recent efforts are made to design secure middlebox services that can directly function over encrypted traffic and middlebox rules. But security concerns from dynamic network functions like stateful deep packet inspection and firewall rule updates are still not yet fully addressed. In this paper, we first propose a practical system architecture for outsourced middleboxes to perform dynamic deep packet inspection with forward and backward privacy. That is, newly added rules cannot be linked to previous inspection results, and deleted rules remain inaccessible to the server. Several recent papers have shown that it is a strong property that makes adaptive attacks less effective. Furthermore, we provide a generic solution that handles stateful inspection while still ensuring the state privacy protection. Rigorous analysis and prototype evaluations demonstrate the security, efficiency, and effectiveness of the design.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
Robot完成签到 ,获得积分10
1秒前
酒吧舞男茜茜妈完成签到,获得积分10
2秒前
fendy发布了新的文献求助50
2秒前
量子星尘发布了新的文献求助10
3秒前
王小贝完成签到,获得积分10
3秒前
简单的沛蓝完成签到 ,获得积分10
4秒前
科研通AI6.1应助完美问枫采纳,获得10
5秒前
超级欧皇的好宝宝完成签到 ,获得积分10
7秒前
8秒前
9秒前
9秒前
10秒前
11秒前
12秒前
cl完成签到 ,获得积分10
12秒前
13秒前
bkagyin应助pure123采纳,获得30
13秒前
完美问枫完成签到,获得积分10
13秒前
hotcas发布了新的文献求助10
14秒前
crethy完成签到,获得积分10
14秒前
1995ggw发布了新的文献求助10
15秒前
子平完成签到 ,获得积分0
15秒前
15秒前
研友_VZG7GZ应助One采纳,获得10
16秒前
16秒前
Jason发布了新的文献求助10
17秒前
17秒前
18秒前
Homura完成签到,获得积分10
18秒前
欣喜的涵柏完成签到 ,获得积分10
18秒前
深情安青应助萌only采纳,获得10
18秒前
GingerF应助jam采纳,获得10
21秒前
sun发布了新的文献求助10
21秒前
lqf发布了新的文献求助10
21秒前
七月完成签到,获得积分10
21秒前
量子星尘发布了新的文献求助10
21秒前
22秒前
23秒前
七月发布了新的文献求助10
24秒前
25秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Encyclopedia of Forensic and Legal Medicine Third Edition 5000
Introduction to strong mixing conditions volume 1-3 5000
Agyptische Geschichte der 21.30. Dynastie 3000
Aerospace Engineering Education During the First Century of Flight 2000
从k到英国情人 1700
„Semitische Wissenschaften“? 1510
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5774852
求助须知:如何正确求助?哪些是违规求助? 5620046
关于积分的说明 15436926
捐赠科研通 4907323
什么是DOI,文献DOI怎么找? 2640592
邀请新用户注册赠送积分活动 1588479
关于科研通互助平台的介绍 1543394