首页> 外文会议>Intl Conference on Big Data Security on Cloud >A Policy Based Framework for Privacy-Respecting Deep Packet Inspection of High Velocity Network Traffic
【24h】

A Policy Based Framework for Privacy-Respecting Deep Packet Inspection of High Velocity Network Traffic

机译:基于策略的隐私框架尊重高速网络流量的深度分组检查

获取原文

摘要

Deep Packet Inspection (DPI) is instrumental in investigating the presence of malicious activity in network traffic and most existing DPI tools work on unencrypted payloads. As the internet is moving towards fully encrypted data-transfer, there is a critical requirement for privacy-aware techniques to efficiently decrypt network payloads. Until recently, passive proxying using certain aspects of TLS 1.2 were used to perform decryption and further DPI analysis. With the introduction of TLS 1.3 standard that only supports protocols with Perfect Forward Secrecy (PFS), many such techniques will become ineffective. Several security solutions will be forced to adopt active proxying that will become a big-data problem considering the velocity and veracity of network traffic involved. We have developed an ABAC (Attribute Based Access Control) framework that efficiently supports existing DPI tools while respecting user's privacy requirements and organizational policies. It gives the user the ability to accept or decline access decision based on his privileges. Our solution evaluates various observed and derived attributes of network connections against user access privileges using policies described with semantic technologies. In this paper, we describe our framework and demonstrate the efficacy of our technique with the help of use-case scenarios to identify network connections that are candidates for Deep Packet Inspection. Since our technique makes selective identification of connections based on policies, both processing and memory load at the gateway will be reduced significantly.
机译:深度数据包检测(DPI)是在调查网络流量中的恶意活动以及大多数现有DPI工具的情况下的乐器,而不是未加密的有效载荷。随着互联网正在朝着完全加密的数据传输移动,存在有效地解密网络有效载荷的隐私感知技术存在关键要求。直到最近,使用TLS 1.2的某些方面的被动代理用于执行解密和进一步的DPI分析。通过引入TLS 1.3标准,只支持具有完美前锋保密(PFS)的协议,许多这样的技术将无效。考虑所涉及的网络流量的速度和准确性,将强制采用活动代理将采用主动代理。我们开发了ABAC(基于属性的访问控制)框架,其有效地支持现有DPI工具,同时尊重用户的隐私要求和组织策略。它使用户能够根据他的特权接受或拒绝访问决策。我们的解决方案使用用语义技术描述的策略评估对用户访问权限的各种观察和派生的网络连接属性。在本文中,我们描述了我们的框架,并借鉴了在利用情况方案的帮助下识别我们是深度数据包检查的候选网络连接的技术的效果。由于我们的技术基于策略使连接的选择性识别,因此网关的处理和内存负载将显着降低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号