论文标题

迈向实用的加密网络流量模式,以匹配安全的中间箱

Towards Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes

论文作者

Lai, Shangqi, Yuan, Xingliang, Sun, Shi-Feng, Liu, Joseph K., Steinfeld, Ron, Sakzad, Amin, Liu, Dongxi

论文摘要

网络功能虚拟化(NFV)推进了可组合软件中间箱的采用。因此,云数据中心成为企业流量处理的主要NFV供应商。由于交通重定向到云的隐私问题,安全的中间箱系统(例如,盲箱)引起了很多关注。他们可以直接针对加密规则处理加密的数据包。但是,大多数支持基于模式匹配的网络功能的现有系统都需要通过滑动窗口来通往令牌数据包有效载荷的企业网关。这样的象征化引起了相当大的沟通开销,对于数据包大小,可以超过100美元。为了克服这个瓶颈,在本文中,我们提出了第一个针对安全的中间箱的带宽效率加密的模式匹配协议。我们诉诸于一种称为对称的隐藏矢量加密(SHVE)的原始性,并提出了它的变体,也就是SHVE+,以实现恒定和中等的通信成本。为了加快加速,我们设计了加密的过滤器,以减少在高度匹配过程中访问SHVE+的次数。我们对拟议协议的安全性进行正式的安全性,并对实际规则集和交通转储进行全面评估。结果表明,我们的设计可以在100美元$ $ s内检查超过20k规则的数据包。与先前的工作相比,它可以节省94美元的带宽消费。

Network Function Virtualisation (NFV) advances the adoption of composable software middleboxes. Accordingly, cloud data centres become major NFV vendors for enterprise traffic processing. Due to the privacy concern of traffic redirection to the cloud, secure middlebox systems (e.g., BlindBox) draw much attention; they can process encrypted packets against encrypted rules directly. However, most of the existing systems supporting pattern matching based network functions require the enterprise gateway to tokenise packet payloads via sliding windows. Such tokenisation induces a considerable communication overhead, which can be over 100$\times$ to the packet size. To overcome this bottleneck, in this paper, we propose the first bandwidth-efficient encrypted pattern matching protocol for secure middleboxes. We resort to a primitive called symmetric hidden vector encryption (SHVE), and propose a variant of it, aka SHVE+, to achieve constant and moderate communication cost. To speed up, we devise encrypted filters to reduce the number of accesses to SHVE+ during matching highly. We formalise the security of our proposed protocol and conduct comprehensive evaluations over real-world rulesets and traffic dumps. The results show that our design can inspect a packet over 20k rules within 100 $μ$s. Compared to prior work, it brings a saving of $94\%$ in bandwidth consumption.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源