首页> 外文OA文献 >Per-user Policy Enforcement on Mobile Apps through Network Functions Virtualization
【2h】

Per-user Policy Enforcement on Mobile Apps through Network Functions Virtualization

机译:通过网络功能虚拟化对移动应用程序执行每用户策略

摘要

Due to the increasing popularity of smartphones and tablets, mobile apps are becoming the preferred portals for users to access various network services in both residential and enterprise environments. Predominantly using generic HTTP or HTTPS protocols, traffic from different mobile apps is largely indistinguishable. This loss of visibility into mobile app traffic brings new challenges to network management and traffic analysis. It has became very hard to implement network policies based on the differentiation between traffic from compliant and non-compliant mobile apps. This paper presents a system that not only provides network administrators the much desired capability of enforcing policies on mobile app traffic, but also does that at a fine per-user granularity. The proposed system takes a Network Functions Virtualization (NFV) approach and virtualizes an edge router into multiple virtual data planes. Specifically, each data plane serves solely to one particular user and consists of user-specific virtualized network functions. The independence of the virtual data planes facilitates enforcing network policies at the per-user level. To enable policy enforcement on mobile apps, our system includes a sophisticated mobile app identification module to recognize traffic from different apps using preloaded traffic signatures. By exploiting TLS proxying, our system can even enforce policies on those mobile apps adopting traffic encryption. We have implemented a prototype of the proposed system as a wireless access point (AP) using a commodity small form factor PC. Our preliminary experimental evaluations show that the system can scale to modest number of users without much impacting user experience in using the network
机译:由于智能手机和平板电脑的日益普及,移动应用程序已成为用户在住宅和企业环境中访问各种网络服务的首选门户。主要使用通用HTTP或HTTPS协议,来自不同移动应用程序的流量在很大程度上是无法区分的。对移动应用流量的可见性的丧失给网络管理和流量分析带来了新的挑战。基于兼容和不兼容移动应用的流量之间的差异,实施网络策略变得非常困难。本文提出了一种系统,该系统不仅为网络管理员提供了针对移动应用流量实施策略的理想功能,而且还为每个用户提供了很好的粒度。拟议的系统采用网络功能虚拟化(NFV)方法,并将边缘路由器虚拟化为多个虚拟数据平面。具体而言,每个数据平面仅服务于一个特定用户,并且由用户特定的虚拟化网络功能组成。虚拟数据平面的独立性有助于在每个用户级别实施网络策略。为了对移动应用执行策略,我们的系统包括一个复杂的移动应用识别模块,以使用预加载的流量签名来识别来自不同应用的流量。通过利用TLS代理,我们的系统甚至可以对那些采用流量加密的移动应用强制执行策略。我们已经使用商品化的小型PC将拟议系统的原型实现为无线接入点(AP)。我们的初步实验评估表明,该系统可以扩展到适度的用户数量,而不会在很大程度上影响使用网络的用户体验

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号