发表状态 | 已发表Published |
题名 | SlimBox: Lightweight Packet Inspection over Encrypted Traffic |
作者 | |
发表日期 | 2023-09-01 |
发表期刊 | IEEE Transactions on Dependable and Secure Computing
![]() |
ISSN/eISSN | 1545-5971 |
卷号 | 20期号:5页码:4359-4371 |
摘要 | Due to the explosive increase of enterprise network traffic, middleboxes that inspect packets through customized rules have been widely outsourced for cost-saving. Despite promising, redirecting enterprise traffic to remote middleboxes raises privacy concerns about the exposure of corporate secrets. To address this, existing solutions mainly apply searchable encryption (SE) to encrypt traffic and rules, enabling middlebox to perform pattern matching over ciphertexts without learning any sensitive information. However, SE is designed for searching pre-chosen keywords, and may cause extensive costs when applied directly to inspecting traffic in which the keywords cannot be determined in advance. The inefficiency of existing SE-based approaches motivates us to investigate a privacy-preserving and lightweight middlebox. To this end, this paper designs SlimBox, which rapidly screens out potentially malicious packets in constant time while incurring only moderate communication overhead. Our main idea is to fragment a traffic/rule string into sub-patterns to achieve conjunctive sub-pattern matching over ciphertexts, while incorporating the position information into the secure matching process to avoid false positives. Experiment results on real datasets show that SlimBox can achieve a good tradeoff between matching latency and communication cost compared to prior work. |
关键词 | lightweight Outsourced middlebox pattern matching privacy preserving searchable encryption |
DOI | 10.1109/TDSC.2022.3222533 |
URL | 查看来源 |
收录类别 | SCIE |
语种 | 英语English |
WOS研究方向 | Computer Science |
WOS类目 | Computer Science, Hardware & Architecture ; Computer Science, Information Systems ; Computer Science, Software Engineering |
WOS记录号 | WOS:001144489500051 |
Scopus入藏号 | 2-s2.0-85144025595 |
引用统计 | |
文献类型 | 期刊论文 |
条目标识符 | https://repository.uic.edu.cn/handle/39GCC9TT/10929 |
专题 | 理工科技学院 |
通讯作者 | Wang, Guojun |
作者单位 | 1.Hunan University, College of Computer Science and Electronic Engineering, Changsha, Hunan Province, 410082, China 2.Temple University, Department of Computer and Information Sciences, Philadelphia, 19122, United States 3.Beijing Normal University and UIC, Institute of Artificial Intelligence and Future Networks, Zhuhai, Guangdong Province, 519000, China 4.Guangzhou University, School of Computer Science and Cyber Engineering, Guangzhou, Guangdong Province, 510006, China |
推荐引用方式 GB/T 7714 | Liu, Qin,Peng, Yu,Jiang, Hongboet al. SlimBox: Lightweight Packet Inspection over Encrypted Traffic[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20(5): 4359-4371. |
APA | Liu, Qin., Peng, Yu., Jiang, Hongbo., Wu, Jie., Wang, Tian., .. & Wang, Guojun. (2023). SlimBox: Lightweight Packet Inspection over Encrypted Traffic. IEEE Transactions on Dependable and Secure Computing, 20(5), 4359-4371. |
MLA | Liu, Qin,et al."SlimBox: Lightweight Packet Inspection over Encrypted Traffic". IEEE Transactions on Dependable and Secure Computing 20.5(2023): 4359-4371. |
条目包含的文件 | 条目无相关文件。 |
个性服务 |
查看访问统计 |
谷歌学术 |
谷歌学术中相似的文章 |
[Liu, Qin]的文章 |
[Peng, Yu]的文章 |
[Jiang, Hongbo]的文章 |
百度学术 |
百度学术中相似的文章 |
[Liu, Qin]的文章 |
[Peng, Yu]的文章 |
[Jiang, Hongbo]的文章 |
必应学术 |
必应学术中相似的文章 |
[Liu, Qin]的文章 |
[Peng, Yu]的文章 |
[Jiang, Hongbo]的文章 |
相关权益政策 |
暂无数据 |
收藏/分享 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论