...
首页> 外文期刊>Computer communication review >An Untold Story of Middleboxes in Cellular Networks
【24h】

An Untold Story of Middleboxes in Cellular Networks

机译:蜂窝网络中中间盒的不为人知的故事

获取原文
获取原文并翻译 | 示例
           

摘要

The use of cellular data networks is increasingly popular as network coverage becomes more ubiquitous and many diverse user-contributed mobile applications become available. The growing cellular traffic demand means that cellular network carriers are facing greater challenges to provide users with good network performance and energy efficiency, while protecting networks from potential attacks. To better utilize their limited network resources while securing the network and protecting client devices the carriers have already deployed various network policies that influence traffic behavior. Today, these policies are mostly opaque, though they directly impact application designs and may even introduce network vulnerabilities. We present NetPiculet, the first tool that unveils carriers' NAT and firewall policies by conducting intelligent measurement. By running NetPiculet on the major U.S. cellular providers as well as deploying it as a smartphone application in the wild covering more than 100 cellular ISPs, we identified the key NAT and firewall policies which have direct implications on performance, energy, and security. For example, NAT boxes and firewalls set timeouts for idle TCP connections, which sometimes cause significant energy waste on mobile devices. Although most carriers today deploy sophisticated firewalls, they are still vulnerable to various attacks such as battery draining and denial of service. These findings can inform developers in optimizing the interaction between mobile applications and cellular networks and also guide carriers in improving their network configurations.
机译:随着网络覆盖范围的日益普及以及许多不同的用户贡献的移动应用程序的出现,蜂窝数据网络的使用日益普及。日益增长的蜂窝业务需求意味着蜂窝网络运营商在保护用户免受潜在攻击的同时,要为用户提供良好的网络性能和能效面临更大的挑战。为了在保护网络安全和保护客户端设备的同时更好地利用其有限的网络资源,运营商已经部署了各种影响流量行为的网络策略。如今,这些策略几乎是不透明的,尽管它们直接影响应用程序设计,甚至可能引入网络漏洞。我们展示了NetPiculet,这是第一个通过进行智能测量揭示运营商的NAT和防火墙策略的工具。通过在主要的美国蜂窝服务提供商上运行NetPiculet并将其作为智能手机应用程序广泛部署,覆盖100多家蜂窝ISP,我们确定了关键NAT和防火墙策略,这些策略直接影响性能,能源和安全性。例如,NAT盒和防火墙为闲置的TCP连接设置超时,这有时会导致移动设备上的大量能源浪费。尽管当今大多数运营商都部署了复杂的防火墙,但它们仍然容易受到各种攻击,例如耗电和拒绝服务。这些发现可以帮助开发人员优化移动应用程序和蜂窝网络之间的交互,还可以指导运营商改善其网络配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号