Preserving Network Privacy on Fine-grain Path-tracking Using P4-based SDN

Akbari Indra Basuki, D. Rosiyadi, Iwan Setiawan
{"title":"Preserving Network Privacy on Fine-grain Path-tracking Using P4-based SDN","authors":"Akbari Indra Basuki, D. Rosiyadi, Iwan Setiawan","doi":"10.1109/ICRAMET51080.2020.9298588","DOIUrl":null,"url":null,"abstract":"Path-tracking is essential to provide complete information regarding network breach incidents. It records the direction of the attack and its source of origin thus giving the network manager proper information for the next responses. Nevertheless, the existing path-tracking implementations expose the network topology and routing configurations. In this paper, we propose a privacy-aware path-tracking which mystifies network configurations using in-packet bloom filter. We apply our method by using P4 switch to supports a fine-grain (per-packet) path-tracking with dynamic adaptability via in-switch bloom filter computation. We use a hybrid scheme which consists of a destination-based logging and a path finger print-based marking to minimize the redundant path inferring caused by the bloom filter’s false positive. For evaluation, we emulate the network using Mininet and BMv2 software switch. We deploy a source routing mechanism to run the evaluations using a limited testbed machine implementing Rocketfuel topology. By using the hybrid marking and logging technique, we can reduce the redundant path to zero percent, ensuring no-collision in the path-inferring. Based on the experiments, it has a lower space efficiency (56 bit) compared with the bloom filter-only solution (128 bit). Our proposed method guarantees that the recorded path remains secret unless the secret keys of every switch are known.","PeriodicalId":228482,"journal":{"name":"2020 International Conference on Radar, Antenna, Microwave, Electronics, and Telecommunications (ICRAMET)","volume":"23 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Radar, Antenna, Microwave, Electronics, and Telecommunications (ICRAMET)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICRAMET51080.2020.9298588","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Path-tracking is essential to provide complete information regarding network breach incidents. It records the direction of the attack and its source of origin thus giving the network manager proper information for the next responses. Nevertheless, the existing path-tracking implementations expose the network topology and routing configurations. In this paper, we propose a privacy-aware path-tracking which mystifies network configurations using in-packet bloom filter. We apply our method by using P4 switch to supports a fine-grain (per-packet) path-tracking with dynamic adaptability via in-switch bloom filter computation. We use a hybrid scheme which consists of a destination-based logging and a path finger print-based marking to minimize the redundant path inferring caused by the bloom filter’s false positive. For evaluation, we emulate the network using Mininet and BMv2 software switch. We deploy a source routing mechanism to run the evaluations using a limited testbed machine implementing Rocketfuel topology. By using the hybrid marking and logging technique, we can reduce the redundant path to zero percent, ensuring no-collision in the path-inferring. Based on the experiments, it has a lower space efficiency (56 bit) compared with the bloom filter-only solution (128 bit). Our proposed method guarantees that the recorded path remains secret unless the secret keys of every switch are known.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于p4的SDN细粒度路径跟踪保护网络隐私
路径跟踪对于提供有关网络破坏事件的完整信息至关重要。它记录攻击的方向及其来源,从而为网络管理员提供下一步响应的适当信息。然而,现有的路径跟踪实现公开了网络拓扑和路由配置。在本文中,我们提出了一种隐私感知路径跟踪,它使用包内开花过滤器来使网络配置神秘化。我们通过使用P4交换机,通过交换机内布隆滤波器计算来支持具有动态适应性的细粒度(每包)路径跟踪。我们使用了一种混合方案,该方案由基于目的地的日志记录和基于路径指纹的标记组成,以最大限度地减少由布隆过滤器的假阳性引起的冗余路径推断。为了进行评估,我们使用Mininet和BMv2软件交换机对网络进行了仿真。我们部署了一个源路由机制,使用实现Rocketfuel拓扑的有限测试台机器来运行评估。通过混合标记和记录技术,可以将冗余路径减少到零,保证路径推断不发生碰撞。实验表明,该方案的空间效率(56位)低于纯布隆滤波方案(128位)。我们提出的方法保证记录的路径保持秘密,除非每个交换机的秘密密钥是已知的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Deep Learning for Dengue Fever Event Detection Using Online News Screen Printed Electrochemical Sensor for Ascorbic Acid Detection Based on Nafion/Ionic Liquids/Graphene Composite on Carbon Electrodes Implementation Array-Slotted Miliwires in Artificial Dielectric Material on Waveguide Filters Te10 Mode Path Loss Model of the Maritime Wireless Communication in the Seas of Indonesia Modeling of Low-Resolution Face Imaging
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1