MINOS: Regulating router dataplane actions in dynamic runtime environments

Lei Xu, Ke Xu, Meng Shen, Kui Ren, Jingyuan Fan, Chaowen Guan, Wen Long Chen

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

Programmable routers are emerging as a promising alternative which facilitates the deployment of new network technologies, for example, software-defined networking; meanwhile, theirs programmability and openness also bring risks of security vulnerabilities. Prior work has concentrated on code security and encryption to improve router action honesty. In this paper, we exploit the feasibility of regulating actions on run-time dataplanes by detecting unexpected packet processing operations, which finally provides an honest and backdoor-proof router to operators. The main challenge is to monitor and regulate the action of router dataplane in dynamic runtime environment. Hence we propose Minos, a framework to regulate router actions on dataplanes. Minos takes Action Identifier (AID) as input to perform lookups in a pre-defined white list called Regulated Action Table (RAT), and it finally verifies that the action is (ab)normal. In the end, Minos achieves a pair of irreconcilable goals for security, i.e., costs and effectiveness. We implement and evaluate Minos on Click and DPDK, separately. And our evaluation results show that Minos captures mal-actions with 2 mega-byte spatial costs and no more than 9% performance loss in both Click and DPDK.

源语言英语
主期刊名Proceedings of the ACM Turing 50th Celebration Conference - China, ACM TUR-C 2017
出版商Association for Computing Machinery
ISBN(电子版)9781450348737
DOI
出版状态已出版 - 12 5月 2017
活动50th ACM Turing Conference - China, ACM TUR-C 2017 - Shanghai, 中国
期限: 12 5月 201714 5月 2017

出版系列

姓名ACM International Conference Proceeding Series
Part F127754

会议

会议50th ACM Turing Conference - China, ACM TUR-C 2017
国家/地区中国
Shanghai
时期12/05/1714/05/17

指纹

探究 'MINOS: Regulating router dataplane actions in dynamic runtime environments' 的科研主题。它们共同构成独一无二的指纹。

引用此