Paper 2020/020
Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes
Shangqi Lai, Xingliang Yuan, Shi-Feng Sun, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, and Dongxi Liu
Abstract
Network Function Virtualisation (NFV) advances the adoption of composable software middleboxes. Accordingly, cloud data centres become major NFV vendors for enterprise traffic processing. Due to the privacy concern of traffic redirection to the cloud, secure middlebox systems (e.g., BlindBox) draw much attention; they can process encrypted packets against encrypted rules directly. However, most of the existing systems supporting pattern matching based network functions require the enterprise gateway to tokenise packet payloads via sliding windows. Such tokenisation induces a considerable communication overhead, which can be over 100
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Published elsewhere. IEEE Transactions on Dependable and Secure Computing
- DOI
- 10.1109/TDSC.2021.3065652
- Keywords
- Privacy-PreservingMiddleboxPattern Matching
- Contact author(s)
- shangqi lai @ monash edu
- History
- 2021-04-17: last of 2 revisions
- 2020-01-07: received
- See all versions
- Short URL
- https://ia.cr/2020/020
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2020/020, author = {Shangqi Lai and Xingliang Yuan and Shi-Feng Sun and Joseph K. Liu and Ron Steinfeld and Amin Sakzad and Dongxi Liu}, title = {Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes}, howpublished = {Cryptology {ePrint} Archive, Paper 2020/020}, year = {2020}, doi = {10.1109/TDSC.2021.3065652}, url = {https://eprint.iacr.org/2020/020} }