UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

Fast privacy-preserving network function outsourcing

Asghar, HJ; De Cristofaro, E; Jourjon, G; Kaafar, MA; Mathy, L; Melis, L; Russell, C; (2019) Fast privacy-preserving network function outsourcing. Computer Networks , 163 10.1016/j.comnet.2019.106893. Green open access

[thumbnail of De Cristofaro_AAM_Splitbox.pdf]
Preview
Text
De Cristofaro_AAM_Splitbox.pdf - Accepted Version

Download (836kB) | Preview

Abstract

In this paper, we present the design and implementation of SplitBox, a system for privacy-preserving processing of network functions outsourced to cloud middleboxes—i.e., without revealing the policies governing these functions. SplitBox is built to provide privacy for a generic network function that abstracts the functionality of a variety of network functions and associated policies, including firewalls, virtual LANs, network address translators (NATs), deep packet inspection, and load balancers. We present a scalable design aiming to provide high throughput and low latency, by distributing functionalities to a few virtual machines (VMs), while providing provably secure guarantees. We implement SplitBox inside FastClick, an extension of the Click modular router, using Intel's DPDK to handle packet I/O. We evaluate our prototype experimentally to find its bottlenecks and stress-test its different components, vis-à-vis two widely used network functions, i.e., firewall and VLAN tagging. Our evaluation shows that, on commodity hardware, SplitBox can process packets close to line rate (i.e., 8.9Gbps) with up to 50 traversed policies.

Type: Article
Title: Fast privacy-preserving network function outsourcing
Open access status: An open access version is available from UCL Discovery
DOI: 10.1016/j.comnet.2019.106893
Publisher version: https://doi.org/10.1016/j.comnet.2019.106893
Language: English
Additional information: This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions.
Keywords: NFV, Privacy, Middlebox
UCL classification: UCL
UCL > Provost and Vice Provost Offices
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science
URI: https://discovery.ucl.ac.uk/id/eprint/10082041
Downloads since deposit
0Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item