首页> 外文会议>IEEE Global Communications Conference >A Firewall of Two Clouds: Preserving Outsourced Firewall Policy Confidentiality with Heterogeneity
【24h】

A Firewall of Two Clouds: Preserving Outsourced Firewall Policy Confidentiality with Heterogeneity

机译:两云防火墙:利用异构性保护外包防火墙策略的机密性

获取原文

摘要

It is increasingly common for enterprises and other organizations to outsource firewalls to public clouds in order to reduce the cost and complexity in deploying and maintaining dedicated hardware middleboxes. However, this poses a serious threat to the enterprise network security because sensitive network policies, such as firewall rules, are revealed to cloud providers, which may be leaked and exploited by attackers. In this paper, we design and implement a SE- FWaaS, a secured system that enables cloud providers to support middlebox (e.g., firewall) outsourcing while preserving the network policy confidentiality. The key ingredients in our SE-FWaaS are the distribution of the firewall primitives, namely policy checking and verdict enforcing, to two independent public clouds, and the enabling techniques of efficient firewall rule obfuscation and oblivious rule-matching. Our SE-FWaaS provides the maximum achievable level of protection of network policies by enforcing the principle of the least privilege and removing the threat of offline probing attacks. We evaluate the proposed system over real-world firewall rules and demonstrate its effectiveness and feasibility.
机译:企业和其他组织将防火墙外包给公共云以降低部署和维护专用硬件中间盒的成本和复杂性越来越普遍。但是,这对企业网络安全构成了严重威胁,因为敏感的网络策略(例如防火墙规则)会泄露给云提供商,这些云策略可能会被攻击者泄漏和利用。在本文中,我们设计并实现了SE-FWaaS,这是一个安全的系统,可使云提供商在支持网络策略机密性的同时支持中间盒(例如防火墙)外包。我们SE-FWaaS的关键要素是将防火墙原语(即策略检查和判决执行)分发到两个独立的公共云,以及有效的防火墙规则混淆和遗忘规则匹配的启用技术。我们的SE-FWaaS通过实施最小特权原则并消除了脱机探测攻击的威胁,从而提供了最大程度的网络策略保护。我们根据实际的防火墙规则评估了拟议的系统,并证明了其有效性和可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号