Enabling Secure and Dynamic Deep Packet Inspection in Outsourced Middleboxes

计算机科学 深包检验 网络数据包 计算机网络 计算机安全
作者
Yu Guo,Cong Wang,Xiaohua Jia
标识
DOI:10.1145/3201595.3201601
摘要

Outsourced middlebox services have been a natural trend in modern enterprise networks to handle advanced traffic processing such as deep packet inspection, traffic classification, and load balancing. However, traffic redirection to outsourced middleboxes raises new security and privacy concerns, as this service model gives cloud providers full access to all the enterprise's traffic flows and proprietary middlebox rules. To ease these concerns, recent efforts are made to design secure middlebox services that can directly function over encrypted traffic and middlebox rules. But security concerns from dynamic network functions like stateful deep packet inspection and firewall rule updates are still not yet fully addressed. In this paper, we first propose a practical system architecture for outsourced middleboxes to perform dynamic deep packet inspection with forward and backward privacy. That is, newly added rules cannot be linked to previous inspection results, and deleted rules remain inaccessible to the server. Several recent papers have shown that it is a strong property that makes adaptive attacks less effective. Furthermore, we provide a generic solution that handles stateful inspection while still ensuring the state privacy protection. Rigorous analysis and prototype evaluations demonstrate the security, efficiency, and effectiveness of the design.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
852应助甜蜜的阿飞采纳,获得10
1秒前
5秒前
zcvxd完成签到,获得积分10
5秒前
5秒前
东方雨季完成签到,获得积分10
5秒前
思源应助迷路的钻石采纳,获得10
5秒前
123发布了新的文献求助10
5秒前
lizhaoyu完成签到,获得积分10
6秒前
怡然的怀莲完成签到 ,获得积分10
6秒前
sail发布了新的文献求助30
7秒前
wanci应助缺粥采纳,获得10
8秒前
guoguo完成签到,获得积分10
9秒前
WJY完成签到,获得积分10
9秒前
10秒前
10秒前
11秒前
Shan完成签到,获得积分10
11秒前
Lucas应助wr0112采纳,获得10
11秒前
胡真完成签到 ,获得积分10
11秒前
Ann发布了新的文献求助30
12秒前
paul发布了新的文献求助10
12秒前
zyj完成签到,获得积分10
12秒前
13秒前
Orange应助魔幻的冬寒采纳,获得10
13秒前
Sylvia发布了新的文献求助10
14秒前
15秒前
归尘发布了新的文献求助10
15秒前
面包超人发布了新的文献求助10
16秒前
16秒前
熊小子爱学习完成签到,获得积分10
17秒前
大模型应助zz采纳,获得10
18秒前
小巧曼安发布了新的文献求助10
19秒前
文章哭哭发完成签到,获得积分10
19秒前
19秒前
20秒前
泯恩仇完成签到,获得积分10
20秒前
十七发布了新的文献求助10
20秒前
坚强的广山应助熠熠畅采纳,获得300
20秒前
领导范儿应助缺粥采纳,获得10
20秒前
22秒前
高分求助中
Continuum Thermodynamics and Material Modelling 3000
Production Logging: Theoretical and Interpretive Elements 2700
Mechanistic Modeling of Gas-Liquid Two-Phase Flow in Pipes 2500
Comprehensive Computational Chemistry 1000
Kelsen’s Legacy: Legal Normativity, International Law and Democracy 1000
Conference Record, IAS Annual Meeting 1977 610
Interest Rate Modeling. Volume 3: Products and Risk Management 600
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 有机化学 生物化学 物理 纳米技术 计算机科学 内科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 量子力学 光电子学 冶金
热门帖子
关注 科研通微信公众号,转发送积分 3552436
求助须知:如何正确求助?哪些是违规求助? 3128534
关于积分的说明 9378502
捐赠科研通 2827678
什么是DOI,文献DOI怎么找? 1554508
邀请新用户注册赠送积分活动 725515
科研通“疑难数据库(出版商)”最低求助积分说明 714961