首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >Privacy Preserving Collaborative Enforcement of Firewall Policies in Virtual Private Networks
【24h】

Privacy Preserving Collaborative Enforcement of Firewall Policies in Virtual Private Networks

机译:在虚拟专用网络中保护隐私的防火墙策略的协作实施

获取原文
获取原文并翻译 | 示例

摘要

The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an encrypted tunnel to a VPN server, which, henceforth, allows roaming users to access some resources as if that computer were residing on their home organization's network. Although VPN technology is very useful, it imposes security threats on the remote network because its firewall does not know what traffic is flowing inside the VPN tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to nonoverlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-the-art, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is three to four orders of magnitude faster than CDCF.
机译:广泛部署的虚拟专用网(VPN)技术允许漫游用户建立通向VPN服务器的加密隧道,此后,漫游用户可以访问某些资源,就像该计算机驻留在其本地组织的网络中一样。尽管VPN技术非常有用,但由于其防火墙不知道VPN隧道内部正在流动的流量,因此对远程网络构成了安全威胁。为了解决此问题,我们提出了VGuard,该框架允许策略所有者和请求所有者在策略所有者不知道请求和请求所有者知道策略的情况下共同确定请求是否满足策略。我们首先提出一种有效的协议,称为Xhash,用于比较,该协议允许两方(每个方都有一个号码)比较它们是否具有相同的号码,而不必彼此透露其号码。然后,我们介绍使用Xhash作为基本构建块的VGuard框架。 VGuard的基本思想是首先将防火墙策略转换为不重叠的数字规则,然后使用Xhash检查请求是否与规则匹配。与代表最新技术的跨域协作防火墙(CDCF)框架相比,VGuard不仅更安全,而且效率更高。在用于处理数据包的实际防火墙策略上,我们的实验结果表明,VGuard比CDCF快三到四个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号