首页> 外文会议>IEEE International Parallel and Distributed Processing Symposium >Mitigating Traffic-based Side Channel Attacks Bandwidth-efficient Cloud Storage
【24h】

Mitigating Traffic-based Side Channel Attacks Bandwidth-efficient Cloud Storage

机译:缓解基于流量的侧频攻击带宽有效的云存储

获取原文

摘要

Data deduplication is able to effectively identify and eliminate redundant data and only maintain a single copy of files and chunks. Hence, it is widely used in distributed storage systems and cloud storage to save the users' network bandwidth for uploading files. However, the occurrence of deduplication can be easily identified by monitoring and analyzing network traffic, which leads to the risk of user privacy leakage. An attacker can carry out a very dangerous side channel attack, i.e., learn-the-remaining-information (LRI) attack, to reveal users' privacy information by exploiting the side channel of network traffic in deduplication. Existing work addresses the LRI attack at the cost of the high bandwidth consumption. In order to address this problem, we propose a simple yet effective scheme, called randomized redundant chunk scheme (RRCS), to significantly mitigate the risk of the LRI attack while maintaining the high bandwidth efficiency of deduplication. The idea behind RRCS is to add randomized redundant chunks to mix up the real deduplication states of files used for the LRI attack, which effectively obfuscates the view of the attacker, who attempts to exploit the side channel of network traffic for the LRI attack. Our security analysis shows that RRCS significantly mitigates the risk of the LRI attack. We have implemented the RRCS prototype and evaluated it by using three real-world datasets. Experimental results demonstrate RRCS significantly outperforms existing work in terms of bandwidth efficiency.
机译:数据重复数据删除能够有效地识别和消除冗余数据,只能维护单个文件和块。因此,它广泛用于分布式存储系统和云存储器,以保存用于上传文件的用户网络带宽。然而,通过监控和分析网络流量,可以容易地识别重复数据删除的发生,这导致用户隐私泄漏的风险。攻击者可以通过利用重复数据删除中的网络流量的侧通道来执行非常危险的侧频攻击,即,学习 - 剩余信息(LRI)攻击,以透露用户的隐私信息。现有工作以高带宽消耗的成本解决了LRI攻击。为了解决这个问题,我们提出了一种简单而有效的方案,称为随机冗余块方案(RRC),以显着降低LRI攻击的风险,同时保持重复数据删除的高带宽效率。 RRC背后的想法是添加随机的冗余块来混合用于LRI攻击的文件的实际重复数据删除状态,这有效地混淆了攻击者的视图,他们试图利用网络流量的副频道进行LRI攻击。我们的安全分析表明,RRCS显着降低了LRI攻击的风险。我们已经实现了RRCS原型并通过使用三个现实世界数据集进行评估。实验结果表明RRC在带宽效率方面显着优于现有的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号