...
首页> 外文期刊>IEEE/ACM Transactions on Networking >High-Speed Prefix-Preserving IP Address Anonymization for Passive Measurement Systems
【24h】

High-Speed Prefix-Preserving IP Address Anonymization for Passive Measurement Systems

机译:无源测量系统的高速保留前缀IP地址匿名化

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Passive network measurement and packet header trace collection are vital tools for network operation and research. To protect a user's privacy, it is necessary to anonymize header fields, particularly IP addresses. To preserve the correlation between IP addresses, prefix-preserving anonymization has been proposed. The limitations of this approach for a high-performance measurement system are the need for complex cryptographic computations and potentially large amounts of memory. We propose a new prefix-preserving anonymization algorithm, top-hash subtree-replicated anonymization (TSA), that features three novel improvements: precomputation, replicated subtrees, and top hashing. TSA makes anonymization practical to be implemented on network processors or dedicated logic at Gigabit rates. The performance of TSA is compared with a conventional cryptography based prefix-preserving anonymization scheme which utilizes caching. TSA performs better as it requires no online cryptographic computation and a small number of memory lookups per packet. Our analytic comparison of the susceptibility to attacks between conventional anonymization and our approach shows that TSA performs better for small scale attacks and comparably for medium scale attacks. The processing cost for TSA is reduced by two orders of magnitude and the memory requirements are a few Megabytes. The ability to tune the memory requirements and security level makes TSA ideal for a broad range of network systems with different capabilities
机译:被动网络测量和数据包头跟踪收集是网络运营和研究的重要工具。为了保护用户的隐私,必须匿名化标头字段,尤其是IP地址。为了保持IP地址之间的相关性,已经提出了保留前缀的匿名化。这种方法对高性能测量系统的局限性是需要复杂的密码计算和潜在的大量内存。我们提出了一种新的保留前缀的匿名化算法,即top-hash子树复制匿名化(TSA),它具有三个新颖的改进:预计算,复制的子树和top哈希。 TSA使匿名化切实可行地以千兆位速率在网络处理器或专用逻辑上实现。将TSA的性能与使用缓存的基于常规密码术的保留前缀的匿名方案进行比较。 TSA的性能更好,因为它不需要在线密码计算,并且每个数据包只需要少量的内存查找。我们对传统匿名化与我们的方法之间的攻击敏感性进行的分析比较表明,TSA在小规模攻击方面表现更好,在中型攻击方面表现更好。 TSA的处理成本降低了两个数量级,并且内存需求只有几兆字节。调整内存需求和安全级别的能力使TSA成为具有不同功能的各种网络系统的理想选择

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号