跳到主要导航 跳到搜索 跳到主要内容

FlowShredder: A Protocol-Independent in-Network Security Service in the Cloud

  • Bin Song
  • , Bin Sun
  • , Qiang Fu
  • , Hao Li
  • Xi'an Jiaotong University
  • Royal Melbourne Institute of Technology University

科研成果: 书/报告/会议事项章节会议稿件同行评审

1 引用 (Scopus)

摘要

Cloud services increasingly generates enormous Internet traffic. Much of it such as rich media traffic is not highly sensitive, but prefers some sort of protection. The traditional end-to-end encryption such as TLS is costly and has issues such as increased latency, while the simple anonymity solutions cannot resist traffic analysis attacks. In this paper, we propose FlowShredder, a protocol-independent and in-network service to secure such traffic in the cloud. FlowShredder aims to break the association between packets, data flow and hosts by obfuscating the packet header (some payload if needed). Without the context of flow and hosts, packets are of little value to the adversary. The operation is carried out at cloud gateways, without encrypting the payload. Its simple logic can therefore be executed within a single pipeline of the Tofino programmable switch, to ensure wire-speed performance without the scalability issue. Being protocol-independent and operating in-network at wire speed make FlowShredder a practical and generic security service to protect the cloud traffic. In addition, FlowShredder can work with end-to-end encryption such as 0-RTT TLS for enhanced protection. We implement FlowShredder in P4 switches. Experiments show that FlowShredder can effectively resist the traffic analysis attack with supervised learning techniques.

源语言英语
主期刊名Service-Oriented Computing - 22nd International Conference, ICSOC 2024, Proceedings
编辑Walid Gaaloul, Michael Sheng, Qi Yu, Sami Yangui
出版商Springer Science and Business Media Deutschland GmbH
327-334
页数8
ISBN(印刷版)9789819608041
DOI
出版状态已出版 - 2025
活动22nd International Conference on Service-Oriented Computing, ICSOC 2024 - Tunis, 突尼斯
期限: 3 12月 20246 12月 2024

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
15404 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议22nd International Conference on Service-Oriented Computing, ICSOC 2024
国家/地区突尼斯
Tunis
时期3/12/246/12/24

学术指纹

探究 'FlowShredder: A Protocol-Independent in-Network Security Service in the Cloud' 的科研主题。它们共同构成独一无二的指纹。

引用此