• DocumentCode
    85512
  • Title

    The Silence of the LANs: Efficient Leakage Resilience for IPsec VPNs

  • Author

    Schulz, Stephan ; Varadharajan, Vijay ; Sadeghi, Ahmad-Reza

  • Author_Institution
    Syst. Security Labs., Ruhr-Univ. Bochum, Bochum, Germany
  • Volume
    9
  • Issue
    2
  • fYear
    2014
  • fDate
    Feb. 2014
  • Firstpage
    221
  • Lastpage
    232
  • Abstract
    Virtual private networks (VPNs) are increasingly used to build logically isolated networks. However, existing VPN designs and deployments neglected the problem of traffic analysis and covert channels. Hence, there are many ways to infer information from VPN traffic without decrypting it. Many proposals have been made to mitigate network covert channels, but previous works remained largely theoretical or resulted in prohibitively high padding overhead and performance penalties. In this paper, we: 1) analyse the impact of covert channels in IPsec; 2) present several improved and novel approaches for covert channel mitigation in IPsec; 3) propose and implement a system for dynamic performance trade-offs; and 4) implement our design in the Linux IPsec stack and evaluate its performance for different types of traffic and mitigation policies. At only 24% overhead, our prototype enforces tight information-theoretic bounds on information leakage. To encourage further research, we put our prototype code and data in the public domain.
  • Keywords
    IP networks; Linux; computer network performance evaluation; local area networks; telecommunication traffic; virtual private networks; IPsec VPN; LAN; Linux IPsec stack; VPN deployment; VPN design; VPN traffic; covert channel mitigation; dynamic performance trade-offs; information leakage; information-theoretic bounds; leakage resilience; logically isolated networks; mitigation policy; network covert channels; padding overhead; performance evaluation; performance penalty; traffic analysis; traffic policy; virtual private networks; IP networks; Local area networks; Logic gates; Security; Throughput; Virtual private networks; Wide area networks; IPsec; VPNs; covert channels; performance; trade-off;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2013.2289978
  • Filename
    6657768