Traffic Flow Confidentiality in IPsec: Protocol and Implementation

Traffic Flow Confidentiality in IPsec: Protocol and Implementation
复制标题

IPsec 中的流量机密性:协议和实现

DOI:
10.1007/978-0-387-79026-8_22
复制
发表时间:
2007
期刊:
Comput. Commun. Rev.
影响因子:
--
通讯作者:
Emanuele Delzeri
Emanuele Delzeri
中科院分区:
--
文献类型:
--
作者:
C. Király;S. Teofili;G. Bianchi;R. Cigno;Matteo Nardelli;Emanuele Delzeri

文献摘要

被引文献

相似文献

流量保密(TFC)机制是设计用于隐藏/伪装流量模式以防止统计流量分析攻击的技术。将它们纳入广泛的安全协议,再加上部署者灵活控制其操作的能力,可能会促进它们的采用并改善未来网络的隐私。本文描述了一个TFC协议集成,作为一个安全协议,在GPRS安全体系结构。已经开发了一个基于Linux的实现,以一种容易组合的方式支持各种每包处理(填充,分段,虚拟数据包生成和人为改变数据包转发延迟)。实验结果表明,TFC实现的灵活性和有效性。
Traffic Flow Confidentiality (TFC) mechanisms are techniques devised to hide/masquerade the traffic pattern to prevent statistical traffic analysis attacks. Their inclusion in widespread security protocols, in conjunction with the ability for deployers to flexibly control their operation, might boost their adoption and improve privacy of future networks. This paper describes a TFC protocol integrated, as a security protocol, in the IPsec security architecture. A Linux-based implementation has been developed, supporting a variety of perpacket treatments (padding, fragmentation, dummy packet generation, and artificial alteration of the packet forwarding delay), in an easily combinable manner. Experimental results are reported to demonstrate the flexibility and the effectiveness of the TFC implementation.