DocumentCode
1994817
Title
Design and Implementation of Cross-Domain Cooperative Firewall
Author
Cheng, Jerry ; Yang, Hao ; Wong, Starsky H Y ; Zerfos, Petros ; Lu, Songwu
Author_Institution
UCLA Comput., Los Angeles
fYear
2007
fDate
16-19 Oct. 2007
Firstpage
284
Lastpage
293
Abstract
Security and privacy are two major concerns in supporting roaming users across administrative domains. In current practices, a roaming user often uses encrypted tunnels, e.g., Virtual Private Networks (VPNs), to protect the secrecy and privacy of her communications. However, due to its encrypted nature, the traffic flowing through these tunnels cannot be examined and regulated by the foreign network´s firewall, which may lead the foreign network widely open to various attacks from the Internet. This threat can be alleviated if the users reveal their traffic to the foreign network or the foreign network reveals its firewall rules to the tunnel endpoints. However, neither approach is desirable in practice due to privacy concerns. In this paper, we propose a Cross-Domain Cooperative Firewall (CDCF) that allows two collaborative networks to enforce each other´s firewall rules in an oblivious manner. In CDCF, when a roaming user establishes an encrypted tunnel between his home network and the foreign network, the tunnel endpoint (e.g., a VPN server) can regulate the traffic and enforce the foreign network´s firewall rules, without knowing these rules. The key ingredients in CDCF are the distribution of firewall primitives across network domains, and the enabling technique of efficient oblivious membership verification. We have implemented CDCF and integrated it with the OpenVPN software, and evaluated its performance using extensive experiments. Our results show that CDCF can protect the foreign network from encrypted tunnel traffic with minimal overhead.
Keywords
authorisation; computer networks; cryptography; virtual private networks; OpenVPN software; cross-domain cooperative firewall; encrypted tunnels; user privacy; user security; virtual private networks; Collaborative work; Cryptography; Home automation; IP networks; Network servers; Privacy; Protection; Software performance; Telecommunication traffic; Virtual private networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Protocols, 2007. ICNP 2007. IEEE International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-1588-5
Electronic_ISBN
978-1-4244-1588-5
Type
conf
DOI
10.1109/ICNP.2007.4375859
Filename
4375859
Link To Document