Enabling Secure and Dynamic Deep Packet Inspection in Outsourced Middleboxes

计算机科学 深包检验 网络数据包 计算机网络 计算机安全
作者
Yu Guo,Cong Wang,Xiaohua Jia
标识
DOI:10.1145/3201595.3201601
摘要

Outsourced middlebox services have been a natural trend in modern enterprise networks to handle advanced traffic processing such as deep packet inspection, traffic classification, and load balancing. However, traffic redirection to outsourced middleboxes raises new security and privacy concerns, as this service model gives cloud providers full access to all the enterprise's traffic flows and proprietary middlebox rules. To ease these concerns, recent efforts are made to design secure middlebox services that can directly function over encrypted traffic and middlebox rules. But security concerns from dynamic network functions like stateful deep packet inspection and firewall rule updates are still not yet fully addressed. In this paper, we first propose a practical system architecture for outsourced middleboxes to perform dynamic deep packet inspection with forward and backward privacy. That is, newly added rules cannot be linked to previous inspection results, and deleted rules remain inaccessible to the server. Several recent papers have shown that it is a strong property that makes adaptive attacks less effective. Furthermore, we provide a generic solution that handles stateful inspection while still ensuring the state privacy protection. Rigorous analysis and prototype evaluations demonstrate the security, efficiency, and effectiveness of the design.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
1秒前
搜集达人应助小小文采纳,获得10
1秒前
2秒前
2秒前
yu完成签到,获得积分10
3秒前
xc发布了新的文献求助10
4秒前
wzs发布了新的文献求助10
4秒前
星星国王发布了新的文献求助10
6秒前
勤劳语山完成签到,获得积分10
6秒前
murph0622发布了新的文献求助10
7秒前
机智毛豆完成签到,获得积分10
7秒前
8秒前
8秒前
吃撑了去减肥关注了科研通微信公众号
10秒前
11秒前
情怀应助dcgz采纳,获得10
12秒前
科研通AI6应助ShengzhangLiu采纳,获得10
13秒前
Rosie完成签到,获得积分10
14秒前
无花果应助hmv采纳,获得10
14秒前
xinxin发布了新的文献求助10
14秒前
14秒前
yuzhecheng发布了新的文献求助10
15秒前
王丹丹发布了新的文献求助10
15秒前
阿九发布了新的文献求助10
16秒前
17秒前
绾妤发布了新的文献求助10
17秒前
mawenxing完成签到,获得积分10
19秒前
萱萱发布了新的文献求助10
20秒前
21秒前
12应助DODODO采纳,获得50
22秒前
24秒前
xinxin完成签到,获得积分10
24秒前
阿盛发布了新的文献求助10
25秒前
25秒前
香蕉觅云应助EF采纳,获得10
26秒前
27秒前
27秒前
lydiaabc完成签到,获得积分10
28秒前
29秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Zeolites: From Fundamentals to Emerging Applications 1500
Encyclopedia of Materials: Plastics and Polymers 1000
Architectural Corrosion and Critical Infrastructure 1000
Early Devonian echinoderms from Victoria (Rhombifera, Blastoidea and Ophiocistioidea) 1000
Hidden Generalizations Phonological Opacity in Optimality Theory 1000
Handbook of Social and Emotional Learning, Second Edition 900
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 内科学 生物化学 物理 计算机科学 纳米技术 遗传学 基因 复合材料 化学工程 物理化学 病理 催化作用 免疫学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 4924525
求助须知:如何正确求助?哪些是违规求助? 4194571
关于积分的说明 13029123
捐赠科研通 3966454
什么是DOI,文献DOI怎么找? 2173951
邀请新用户注册赠送积分活动 1191426
关于科研通互助平台的介绍 1100971