SICS: Secure and Dynamic Middlebox Outsourcing

SICS: Secure and Dynamic Middlebox Outsourcing
复制标题

DOI:
10.1109/tnet.2020.3023386
复制
发表时间:
2020-12
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Huazhe Wang;Xin Li;Chen Qian
Huazhe Wang;Xin Li;Chen Qian
中科院分区:
其他
文献类型:
--
作者:
Huazhe Wang;Xin Li;Chen Qian

文献摘要

相似文献

越来越多的企业将其中间盒处理外包给云,以降低成本和更容易管理。然而,外包中间盒给企业的隐私信息带来威胁,包括中间盒的流量和规则,这些都在云中可见。现有的安全中间盒外包解决方案要么会产生巨大的性能开销,要么不支持增量更新。在本文中,我们提出了一个安全的、动态的中间盒外包框架SICS,简称Secure In-Cloud Service。SICS对每个数据包头进行加密,并使用标签进行云内规则匹配,从而使云能够以最小的头信息泄漏正确执行其功能。评估结果表明,与现有解决方案相比,SICS实现了更高的吞吐量,更快的构建和更新速度,以及更低的企业和云端资源开销。
There is an increasing trend that enterprises outsource their middlebox processing to a cloud for lower cost and easier management. However, outsourcing middleboxes brings threats to the enterprise’s private information, including the traffic and rules of middleboxes, all of which are visible within the cloud. Existing solutions for secure middlebox outsourcing either incur significant performance overhead or do not support incremental updates. In this article, we present a secure and dynamic middlebox outsourcing framework, SICS, short for Secure In-Cloud Service. SICS encrypts each packet header and uses a label for in-cloud rule matching, which enables the cloud to perform its functionalities correctly with minimum header information leakage. Evaluation results show that SICS achieves higher throughput, faster construction and update speed, and lower resource overhead at the enterprise and in the cloud when compared with existing solutions.