DocumentCode :
3265571
Title :
SEAMS: A Signaling Layer for End-Host-Assisted Middlebox Services
Author :
Hummen, René ; Ziegeldorf, Jan Henrik ; Heer, Tobias ; Wirtz, Hanno ; Wehrle, Klaus
Author_Institution :
Dept. of Commun. & Distrib. Syst., RWTH Aachen Univ., Aachen, Germany
fYear :
2012
fDate :
25-27 June 2012
Firstpage :
525
Lastpage :
532
Abstract :
On-path network elements, such as NATs and firewalls, are an accepted commonality in today´s networks. They are essential when extending network functionality and providing additional security. However, these so called middleboxes are not explicitly considered in the original TCP/IP-based network architecture. As a result, the protocols of the TCP/IP suite provide middleboxes with the same information about data flows as packet-forwarding routers. Yet, middleboxes typically perform complex functions within the network that require additional knowledge. Inferring this knowledge from observing the sparse information available in network packets requires these devices to base their decisions on ambiguous or forgeable data. In this paper, we first discuss problems arising from insufficient information and identify the resulting informational requirements of middleboxes. We then propose SEAMS, a signaling layer that provides middleboxes with descriptive and verifiable data flow contexts in addition to the IP address and port information that many middleboxes use today. Specifically, SEAMS enables middleboxes to request and use detailed information about the host, application, and user that is accessible at the communicating end hosts. This information can then be used to provide more secure and richer middlebox functions in home and enterprise network scenarios. Our evaluation shows that SEAMS is a feasible addition to TCP/IP-based networks and that it scales well in the presence of multiple on-path middleboxes.
Keywords :
computer network security; transport protocols; IP address; SEAMS; TCP/IP-based network architecture; end-host-assisted middlebox services; on-path network elements; packet-forwarding routers; signaling layer; Context; IP networks; Inspection; Middleboxes; Operating systems; Protocols; HIP; authentication; end-host-assisted; in-network; middlebox; security; signaling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4673-2172-3
Type :
conf
DOI :
10.1109/TrustCom.2012.250
Filename :
6296016
Link To Document :
بازگشت