HI,欢迎来到好期刊网,发表咨询:400-888-9411 订阅咨询:400-888-1571证券代码(211862)

TVIDS: Trusted Virtual IDS With SGX

摘要:Network functions such as intrusion detection systems (IDS) have been increasingly deployed as virtual network functions or outsourced to cloud service providers so as to achieve the scalability and agility, and reducing equipment costs and operational cost. However, virtual intrusion detection systems (VIDS) face more serious security threats due to running in a shared and virtualized environment instead of proprietary devices. Cloud service providers or malicious tenants may illegally access and tamper with the policies, packet information, and internal processing states of intrusion detection systems, thereby violating the privacy and security of tenant’s networks. To address these challenges, we use Intel Software Guard Extensions (SGX) to build a Trusted Virtual Intrusion Detection System (TVIDS). For TVIDS, to prevent cloud service providers from accessing sensitive information about the users’ network, we build a trusted execution environment for security policy, packets processing, and internal state so that cloud service providers and other malicious tenants can’t access the protected code, policy, processing states, and packets information of the intrusion detection system. We implemented TVIDS on the basis of the Snort which is a famous open-source IDS and evaluated its results on real SGX hardware.The results show that our method can protect the security of the virtual IDS and brings acceptable performance overhead.

关键词:
  • network  
  • function  
  • virtualization  
  • intrusion  
  • detection  
  • system  
  • sgx  
  • trusted  
  • execution  
  • environment  
作者:
Juan; Wang; Shirong; Hao; Yi; Li; Zhi; Hong; Fei; Yan; Bo; Zhao; Jing; Ma; Huanguo; Zhang
单位:
Key; Laboratory; of; Aerospace; Information; Security; and; Trust; Computing; Ministry; of; Education; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; Hubei; China; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; China; Science; and; Technology; on; Information; Assurance; Laboratory; Beijing; 100072; China
刊名:
中国通信

注:因版权方要求,不能公开全文,如需全文,请咨询杂志社

期刊名称:中国通信

中国通信杂志紧跟学术前沿,紧贴读者,国内刊号为:11-5439/TN。坚持指导性与实用性相结合的原则,创办于2004年,杂志在全国同类期刊中发行数量名列前茅。