TVIDS: Trusted Virtual IDS With SGX

摘要:Network functions such as intrusion detection systems (IDS) have been increasingly deployed as virtual network functions or outsourced to cloud service providers so as to achieve the scalability and agility, and reducing equipment costs and operational cost. However, virtual intrusion detection systems (VIDS) face more serious security threats due to running in a shared and virtualized environment instead of proprietary devices. Cloud service providers or malicious tenants may illegally access and tamper with the policies, packet information, and internal processing states of intrusion detection systems, thereby violating the privacy and security of tenant’s networks. To address these challenges, we use Intel Software Guard Extensions (SGX) to build a Trusted Virtual Intrusion Detection System (TVIDS). For TVIDS, to prevent cloud service providers from accessing sensitive information about the users’ network, we build a trusted execution environment for security policy, packets processing, and internal state so that cloud service providers and other malicious tenants can’t access the protected code, policy, processing states, and packets information of the intrusion detection system. We implemented TVIDS on the basis of the Snort which is a famous open-source IDS and evaluated its results on real SGX hardware.The results show that our method can protect the security of the virtual IDS and brings acceptable performance overhead.

關(guān)鍵詞:
  • network  
  • function  
  • virtualization  
  • intrusion  
  • detection  
  • system  
  • sgx  
  • trusted  
  • execution  
  • environment  
作者:
Juan; Wang; Shirong; Hao; Yi; Li; Zhi; Hong; Fei; Yan; Bo; Zhao; Jing; Ma; Huanguo; Zhang
單位:
Key; Laboratory; of; Aerospace; Information; Security; and; Trust; Computing; Ministry; of; Education; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; Hubei; China; School; of; Cyber; Science; and; Engineering; Wuhan; University; Wuhan; 430072; China; Science; and; Technology; on; Information; Assurance; Laboratory; Beijing; 100072; China
刊名:
中國通信

注:因版權(quán)方要求,不能公開全文,如需全文,請咨詢雜志社

期刊名稱:中國通信

中國通信雜志緊跟學術(shù)前沿,緊貼讀者,國內(nèi)刊號為:11-5439/TN。堅持指導性與實用性相結(jié)合的原則,創(chuàng)辦于2004年,雜志在全國同類期刊中發(fā)行數(shù)量名列前茅。

主站蜘蛛池模板: 日韩免费电影在线观看| 国产日韩综合一区二区性色AV | 中文字幕日韩精品无码内射| 亚洲女初尝黑人巨高清| 免费高清在线影片一区| 国产免费av一区二区三区| 国产香蕉97碰碰视频VA碰碰看 | 国产福利影院在线观看| 天天天操天天天干| 性做久久久久免费看| 无码囯产精品一区二区免费 | 丰满黄蓉跪趴高撅肥臀| 亚洲AV无码潮喷在线观看| 亚洲日产2021三区| 亚洲第一区在线| 伊人任线任你躁| 免费看美女隐私直播| 又大又黄又粗又爽视频| 吃奶摸下的激烈免费视频播放| 国产专区第一页| 国产一级毛片在线| 动漫人物差差差免费动漫在线观看| 亚洲精品视频在线免费| 亚洲五月综合缴情婷婷| 久久久久黑人强伦姧人妻| 三年片在线观看免费观看大全中国| 中文字幕一区二区三匹| 久久国产精品亚洲一区二区| 亚洲一区二区三区电影| 亚洲AV无码乱码麻豆精品国产 | 亚洲视频一区二区在线观看| 亚洲香蕉久久一区二区| 亚洲国产AV一区二区三区四区 | 波多野结衣与上司出差| 欧美高清video| 波多野吉衣一区二区三区在线观看| 肉柳高嫁03集在线播放| 色婷婷在线影院| 男人把j桶进女的屁股的动态| 男人让女人爽30分钟免费| 波多野结衣33|