Skip to main navigation Skip to search Skip to main content

FlowShredder: A Protocol-Independent in-Network Security Service in the Cloud

  • Bin Song
  • , Bin Sun
  • , Qiang Fu
  • , Hao Li
  • Xi'an Jiaotong University
  • Royal Melbourne Institute of Technology University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Cloud services increasingly generates enormous Internet traffic. Much of it such as rich media traffic is not highly sensitive, but prefers some sort of protection. The traditional end-to-end encryption such as TLS is costly and has issues such as increased latency, while the simple anonymity solutions cannot resist traffic analysis attacks. In this paper, we propose FlowShredder, a protocol-independent and in-network service to secure such traffic in the cloud. FlowShredder aims to break the association between packets, data flow and hosts by obfuscating the packet header (some payload if needed). Without the context of flow and hosts, packets are of little value to the adversary. The operation is carried out at cloud gateways, without encrypting the payload. Its simple logic can therefore be executed within a single pipeline of the Tofino programmable switch, to ensure wire-speed performance without the scalability issue. Being protocol-independent and operating in-network at wire speed make FlowShredder a practical and generic security service to protect the cloud traffic. In addition, FlowShredder can work with end-to-end encryption such as 0-RTT TLS for enhanced protection. We implement FlowShredder in P4 switches. Experiments show that FlowShredder can effectively resist the traffic analysis attack with supervised learning techniques.

Original languageEnglish
Title of host publicationService-Oriented Computing - 22nd International Conference, ICSOC 2024, Proceedings
EditorsWalid Gaaloul, Michael Sheng, Qi Yu, Sami Yangui
PublisherSpringer Science and Business Media Deutschland GmbH
Pages327-334
Number of pages8
ISBN (Print)9789819608041
DOIs
StatePublished - 2025
Event22nd International Conference on Service-Oriented Computing, ICSOC 2024 - Tunis, Tunisia
Duration: 3 Dec 20246 Dec 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume15404 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference22nd International Conference on Service-Oriented Computing, ICSOC 2024
Country/TerritoryTunisia
CityTunis
Period3/12/246/12/24

Fingerprint

Dive into the research topics of 'FlowShredder: A Protocol-Independent in-Network Security Service in the Cloud'. Together they form a unique fingerprint.

Cite this