Using trustworthy host-based information in the network

Using trustworthy host-based information in the network
复制标题

在网络中使用基于主机的可信信息

DOI:
--
复制
发表时间:
2012
期刊:
Scalable Trusted Computing
影响因子:
--
通讯作者:
A. Perrig
A. Perrig
中科院分区:
--
文献类型:
--
作者:
Bryan Parno;Zongwei Zhou;A. Perrig

文献摘要

被引文献

相似文献

随着对改进的终端主机安全性的硬件支持变得无处不在,重要的是要考虑如何从这些改进中受益于网络安全和性能。如果可以信任每个终端主机的一部分,则网络基础设施不再需要费力且不精确地重建终端主机已知的数据。通过设计一个称为assayer的通用体系结构,我们探讨了提供基于主机的可信数据的问题,包括有用数据和用户隐私之间的平衡,以及安全和效率之间的权衡。我们还在几个案例研究中评估了这些信息的有用性。我们实现并评估了一个基本的assayer原型。我们的原型在终端主机上只需要不到1,000行代码。终端主机可以在几微秒内对其出站流量进行注释,并且可以高效地检查这些注释;即使是千兆位链路上的数据包级注释也可以进行检查,而吞吐量损失仅为13.1%。
As hardware support for improved endhost security becomes ubiquitous, it is important to consider how network security and performance can benefit from these improvements. If portions of each endhost can be trusted, then network infrastructure no longer needs to arduously and imprecisely reconstruct data already known by the endhosts. Through the design of a general-purpose architecture we call Assayer, we explore issues in providing trusted host-based data, including the balance between useful data and user privacy, and the tradeoffs between security and efficiency. We also evaluate the usefulness of such information in several case studies. We implement and evaluate a basic Assayer prototype. Our prototype requires fewer than 1,000 lines of code on the endhost. Endhosts can annotate their outbound traffic in a few microseconds, and these annotations can be checked efficiently; even packet-level annotations on a gigabit link can be checked with a loss in throughput of only 13.1%.