Traffic masking in IPsec: architecture and implementation

Traffic masking in IPsec: architecture and implementation
复制标题

IPsec 中的流量屏蔽:架构和实现

DOI:
--
复制
发表时间:
2007
期刊:
IST Mobile and Wireless Communications Summit
影响因子:
--
通讯作者:
R. Cigno
R. Cigno
中科院分区:
--
文献类型:
--
作者:
C. Király;Giuseppe Bianchi;Fabrizio Formisano;S. Teofili;R. Cigno

文献摘要

被引文献

相似文献

为了防范统计流量分析攻击,需要设计有效的流量保密机制。这些都是为了改变流量模式,以隐藏有关传输内容的信息,尽管加密,恶意用户可以通过统计分析揭示。这些机制的广泛传播需要将它们嵌入到广泛部署的协议中。本文提出了一个基于XML的框架,旨在执行TFC。这由两个关键组件表征:i)被设计为强制分组填充、分段、伪分组生成和分组转发延迟的人工改变的模块,以及ii)被设计为跨TCP隧道携带信息以允许在接收器侧处的分组处理的TFC报头。所提出的方法已在Linux 2.6内核中实现,并报告了初步的实验结果,以显示其操作。
Protection from statistical traffic analysis attacks calls for effective design of traffic flow confidentiality (TFC) mechanisms. These are devised to alter the traffic pattern in order to hide information about contents transmitted, which, despite encryption, can be revealed by malicious users through statistical analysis. Widespread diffusion of these mechanisms requires embedding them in widely deployed protocols. This paper proposes an IPsec based framework aimed at enforcing TFC. This is characterized by two key components: i) a module designed to enforce packet padding, fragmentation, dummy packet generation, and artificial alteration of the packet forwarding delay, and ii) a TFC header devised to carry information across the IPsec tunnel to allow packet handling at the receiver side. The proposed approach has been implemented in a Linux 2.6 Kernel, and preliminary experimental results are reported to show its operation.