Bento: Safely Bringing Network Function Virtualization to Tor

Bento: Safely Bringing Network Function Virtualization to Tor
复制标题

Bento:将网络功能虚拟化安全地引入 Tor

DOI:
10.1145/3452296.3472919
复制
发表时间:
2021
期刊:
ACM SIGCOMM
影响因子:
--
通讯作者:
Levin, Dave
Levin, Dave
中科院分区:
--
文献类型:
--
作者:
Reininger, Michael;Arora, Arushi;Herwig, Stephen;Francino, Nicholas;Hurst, Jayson;Garman, Christina;Levin, Dave

文献摘要

相似文献

Tor是一个强大而重要的工具,为世界各地的用户提供匿名和审查阻力。然而,在tor中部署新服务是非常困难的——它在很大程度上被降级为代理和隐藏服务——或者对新形式的攻击做出灵活的反应。相反,由于可编程网络的最新进展,例如网络功能虚拟化(NFV)提供了可编程的网络内中间件,“非匿名”Internet服务正以前所未有的方式蓬勃发展。本文试图通过在Tor网络中引入可编程中间件来缩小这一差距。在这种架构中,用户可以在愿意的Tor路由器上安装和运行复杂的“功能”。我们演示了一系列功能,这些功能可以提高匿名性、抗攻击能力、隐藏服务的性能等。我们将介绍一个体系结构Bento的设计和实现,该体系结构可以保护中间盒节点免受其运行的功能的影响,并保护其运行的功能免受其运行的中间盒的影响。我们通过在Tor网络上运行Bento来评估它。我们展示了,只需几行Python,我们就可以显著扩展Tor的功能,以满足用户的匿名需求,并灵活地应对新的威胁。我们将公开我们的代码和数据。
Tor is a powerful and important tool for providing anonymity and censorship resistance to users around the world. Yet it is surprisingly difficult to deploy new services in Tor—it is largely relegated to proxies and hidden services—or to nimbly react to new forms of attack. Conversely, “non-anonymous” Internet services are thriving like never before because of recent advances in programmable networks, such as Network Function Virtualization (NFV) which provides programmable in-network middleboxes.This paper seeks to close this gap by introducing programmable middleboxes into the Tor network. In this architecture, users can install and run sophisticated “functions” on willing Tor routers. We demonstrate a wide range of functions that improve anonymity, resilience to attack, performance of hidden services, and more. We present the design and implementation of an architecture, Bento, that protects middlebox nodes from the functions they run—and protects the functions from the middleboxes they run on.We evaluate Bento by running it on the live Tor network. We show that, with just a few lines of Python, we can significantly extend the capabilities of Tor to meet users' anonymity needs and nimbly react to new threats. We will be making our code and data publicly available.