首页> 外文会议>IEEE International Parallel and Distributed Processing Symposium >Mitigating Traffic-Based Side Channel Attacks in Bandwidth-Efficient Cloud Storage
【24h】

Mitigating Traffic-Based Side Channel Attacks in Bandwidth-Efficient Cloud Storage

机译:在带宽高效的云存储中缓解基于流量的边信道攻击

获取原文

摘要

Data deduplication is able to effectively identify and eliminate redundant data and only maintain a single copy of files and chunks. Hence, it is widely used in distributed storage systems and cloud storage to save the users' network bandwidth for uploading files. However, the occurrence of deduplication can be easily identified by monitoring and analyzing network traffic, which leads to the risk of user privacy leakage. An attacker can carry out a very dangerous side channel attack, i.e., learn-the-remaining-information (LRI) attack, to reveal users' privacy information by exploiting the side channel of network traffic in deduplication. Existing work addresses the LRI attack at the cost of the high bandwidth consumption. In order to address this problem, we propose a simple yet effective scheme, called randomized redundant chunk scheme (RRCS), to significantly mitigate the risk of the LRI attack while maintaining the high bandwidth efficiency of deduplication. The idea behind RRCS is to add randomized redundant chunks to mix up the real deduplication states of files used for the LRI attack, which effectively obfuscates the view of the attacker, who attempts to exploit the side channel of network traffic for the LRI attack. Our security analysis shows that RRCS significantly mitigates the risk of the LRI attack. We have implemented the RRCS prototype and evaluated it by using three real-world datasets. Experimental results demonstrate RRCS significantly outperforms existing work in terms of bandwidth efficiency.
机译:重复数据删除能够有效地识别和消除冗余数据,并且仅维护文件和块的单个副本。因此,它广泛用于分布式存储系统和云存储中,以节省用户用于上传文件的网络带宽。但是,可以通过监视和分析网络流量轻松确定重复数据删除的发生,这会导致用户隐私泄露的风险。攻击者可能会进行非常危险的辅助渠道攻击,即学习剩余信息(LRI)攻击,通过在重复数据删除中利用网络流量的辅助渠道来泄露用户的隐私信息。现有工作以高带宽消耗为代价来解决LRI攻击。为了解决这个问题,我们提出了一种简单而有效的方案,称为随机冗余组方案(RRCS),以在保持高带宽重复数据删除效率的同时显着降低LRI攻击的风险。 RRCS背后的想法是添加随机的冗余块,以混合用于LRI攻击的文件的实际重复数据删除状态,这有效地掩盖了攻击者的视线,后者试图利用网络流量的旁通道进行LRI攻击。我们的安全性分析表明,RRCS大大降低了LRI攻击的风险。我们已经实现了RRCS原型并通过使用三个实际数据集对其进行了评估。实验结果表明,RRCS在带宽效率方面明显优于现有工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号