...
首页> 外文期刊>Concurrency and computation: practice and experience >Practical privacy-preserving deep packet inspection outsourcing
【24h】

Practical privacy-preserving deep packet inspection outsourcing

机译:实用的隐私保护深度数据包检查外包

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Hardware-based middleboxes are ubiquitous in computer networks, which usually incur high deployment and management expenses. A recently arising trend aims to address those problems by outsourcing the functions of traditional hardware-based middleboxes to high volume servers in a cloud. This technology is promising but still faces a few challenges from different aspects, including privacy concerns, middlebox functionality, and performance. In this paper, we propose two practical approaches to implementing a cloud-based DPI middlebox. The outsourced DPI middlebox performs payload inspection over encrypted traffic while preserving the privacy of both communication data and inspection rules. Our first approach employs amodified reversible sketch structure,which is used for efficient error-free membership testing, and our second approach extends the famous AC pattern matching algorithm to the cipher text domain.We utilize unkeyed one-way hash functions instead of complex cryptographic protocols to achieve the privacy preservation requirements. Our system supports a wide range of real-world inspection rules.We conduct evaluations on the ClamAV rule set, and the experiment results demonstrate the effectiveness of our proposals.
机译:基于硬件的中间盒在计算机网络中无处不在,通常会导致高昂的部署和管理费用。最近出现的趋势旨在通过将传统的基于硬件的中间盒的功能外包给云中的大容量服务器来解决这些问题。这项技术很有前途,但仍面临来自不同方面的一些挑战,包括隐私问题,中间盒功能和性能。在本文中,我们提出了两种实用的方法来实现基于云的DPI中间盒。外包的DPI中间盒对加密的流量执行有效负载检查,同时保留通信数据和检查规则的私密性。我们的第一种方法采用经过修改的可逆草图结构,用于有效的无错误成员资格测试,第二种方法将著名的AC模式匹配算法扩展到密文文本域。我们使用非密钥单向哈希函数代替复杂的加密协议达到隐私保护的要求。我们的系统支持各种现实世界的检查规则,我们对ClamAV规则集进行评估,实验结果证明了我们建议的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号