Validating security protocols with cloud-based middleboxes

Validating security protocols with cloud-based middleboxes
复制标题

DOI:
10.1109/cns.2016.7860493
复制
发表时间:
2016-10
期刊:
2016 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Curtis R. Taylor;Craig A. Shue
Curtis R. Taylor;Craig A. Shue
中科院分区:
其他
文献类型:
--
作者:
Curtis R. Taylor;Craig A. Shue

文献摘要

被引文献

相似文献

住宅网络对安全构成了独特的挑战,因为它们是由可能没有安全专业知识的最终用户操作的。住宅网络还包含了一些安全保护不力的设备,例如物联网(IoT)设备,这些设备可能会引入漏洞。在这项工作中,我们介绍了TLSDeputy,一个基于中间盒的系统,以保护住宅网络免受连接到不真实的TLS服务器。通过将该方法与OpenFlow(一种流行的软件定义网络协议)相结合,我们表明,我们可以以最小的性能开销有效地为各种设备提供住宅网络范围的保护。
Residential networks pose a unique challenge for security since they are operated by end-users that may not have security expertise. Residential networks are also home to devices that may have lackluster security protections, such as Internet of Things (IoT) devices, which may introduce vulnerabilities. In this work, we introduce TLSDeputy, a middlebox-based system to protect residential networks from connections to inauthentic TLS servers. By combining the approach with OpenFlow, a popular software-defined networking protocol, we show that we can effectively provide residential network-wide protections across diverse devices with minimal performance overheads.