一级a一级a爱片免费免会员2月|日本成人高清视频A片|国产国产国产国产国产国产国产亚洲|欧美黄片一级aaaaaa|三级片AAA网AAA|国产综合日韩无码xx|中文字幕免费无码|黄色网上看看国外超碰|人人操人人在线观看|无码123区第二区AV天堂

TVIDS: Trusted Virtual IDS With SGX

摘要:Network functions such as intrusion detection systems (IDS) have been increasingly deployed as virtual network functions or outsourced to cloud service providers so as to achieve the scalability and agility, and reducing equipment costs and operational cost. However, virtual intrusion detection systems (VIDS) face more serious security threats due to running in a shared and virtualized environment instead of proprietary devices. Cloud service providers or malicious tenants may illegally access and tamper with the policies, packet information, and internal processing states of intrusion detection systems, thereby violating the privacy and security of tenant’s networks. To address these challenges, we use Intel Software Guard Extensions (SGX) to build a Trusted Virtual Intrusion Detection System (TVIDS). For TVIDS, to prevent cloud service providers from accessing sensitive information about the users’ network, we build a trusted execution environment for security policy, packets processing, and internal state so that cloud service providers and other malicious tenants can’t access the protected code, policy, processing states, and packets information of the intrusion detection system. We implemented TVIDS on the basis of the Snort which is a famous open-source IDS and evaluated its results on real SGX hardware.The results show that our method can protect the security of the virtual IDS and brings acceptable performance overhead.

關(guān)鍵詞:
  • network  
  • function  
  • virtualization  
  • intrusion  
  • detection  
  • system  
  • sgx  
  • trusted  
  • execution  
  • environment  
作者:
Juan; Wang; Shirong; Hao; Yi; Li; Zhi; Hong; Fei; Yan; Bo; Zhao; Jing; Ma; Huanguo; Zhang
單位:
Key; Laboratory; of; Aerospace; Information; Security; and; Trust; Computing; Ministry; of; Education; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; Hubei; China; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; China; Science; and; Technology; on; Information; Assurance; Laboratory; Beijing; 100072; China
刊名:
中國(guó)通信

注:因版權(quán)方要求,不能公開(kāi)全文,如需全文,請(qǐng)咨詢雜志社

期刊名稱:中國(guó)通信

中國(guó)通信雜志緊跟學(xué)術(shù)前沿,緊貼讀者,國(guó)內(nèi)刊號(hào)為:11-5439/TN。堅(jiān)持指導(dǎo)性與實(shí)用性相結(jié)合的原則,創(chuàng)辦于2004年,雜志在全國(guó)同類期刊中發(fā)行數(shù)量名列前茅。