SGX-Box: Enabling Visibility on Encrypted Traffic using a Secure Middlebox Module

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 205
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorHan, Juhyengko
dc.contributor.authorKim, Seong Minko
dc.contributor.authorHa, Jaehyeongko
dc.contributor.authorHan, Dongsuko
dc.date.accessioned2017-12-05T01:34:13Z-
dc.date.available2017-12-05T01:34:13Z-
dc.date.created2017-11-20-
dc.date.created2017-11-20-
dc.date.issued2017-08-04-
dc.identifier.citationACM Asia-Pacific Workshop on Networking-
dc.identifier.urihttp://hdl.handle.net/10203/227317-
dc.description.abstractA network middlebox benefits both users and network operators by offering a wide range of security-related in-network functions, such as web firewalls and intrusion detection systems (IDS). However, the wide usage of encryption protocol restricts functionalities of network middleboxes. This forces network operators and users to make a choice between end-to-end privacy and security. This paper presents SGX-Box, a secure middlebox system that enables visibility on encrypted traffic by leveraging Intel SGX technology. The entire process of SGX-Box ensures that the sensitive information, such as decrypted payloads and session keys, is securely protected within the SGX enclave. SGX-Box provides easyto-use abstraction and a high-level programming language, called SB lang for handling encrypted traffic in middleboxes. It greatly enhances programmability by hiding details of the cryptographic operations and the implementation details in SGX enclave processing. We implement a proof-of-concept IDS using SB lang. Our preliminary evaluation shows that SGX-Box incurs acceptable performance overhead while it dramatically reduces middlebox developer’s effort.-
dc.languageEnglish-
dc.publisherACM-
dc.titleSGX-Box: Enabling Visibility on Encrypted Traffic using a Secure Middlebox Module-
dc.typeConference-
dc.type.rimsCONF-
dc.citation.publicationnameACM Asia-Pacific Workshop on Networking-
dc.identifier.conferencecountryCC-
dc.identifier.conferencelocationHong Kong, China-
dc.identifier.doi10.1145/3106989.3106994-
dc.contributor.localauthorHan, Dongsu-
dc.contributor.nonIdAuthorHan, Juhyeng-
dc.contributor.nonIdAuthorHa, Jaehyeong-
Appears in Collection
EE-Conference Papers(학술회의논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0