DocumentCode :
2446473
Title :
Privacy-preserving cross-domain network reachability quantification
Author :
Chen, Fei ; Bruhadeshwar, Bezawada ; Liu, Alex X.
Author_Institution :
Comput. Sci. & Eng., Michigan State Univ., East Lansing, MI, USA
fYear :
2011
fDate :
17-20 Oct. 2011
Firstpage :
155
Lastpage :
164
Abstract :
Network reachability is one of the key factors for capturing end-to-end network behavior and detecting the violation of security policies. While quantifying network reachability within one administrative domain is already difficult, quantifying network reachability across multiple administrative domains is more difficult because the privacy of security policies becomes a serious concern and needs to be protected through this process. In this paper, we propose the first cross-domain privacy-preserving protocol for quantifying network reachability. Our protocol constructs equivalent representations of the Access Control List (ACL) rules and determines network reachability while preserving the privacy of the individual ACLs. This protocol can accurately determine the network reachability along a network path through different administrative domains. We have implemented and evaluated our protocol on both real and synthetic ACLs. The experimental results show that the online processing time of an ACL with thousands of rules is less than 25 seconds, the comparison time of two ACLs is less than 6 seconds, and the communication cost between two ACLs with thousands of rules is less than 2100 KB.
Keywords :
computer network security; cryptographic protocols; ACL rules; access control list rules; administrative domain; communication cost; cross-domain privacy-preserving protocol; end-to-end network; network path; online processing time; privacy-preserving cross-domain network reachability quantification; security policy; Access control; Encryption; Privacy; Protocols; Transforms;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Protocols (ICNP), 2011 19th IEEE International Conference on
Conference_Location :
Vancouver, BC
Print_ISBN :
978-1-4577-1392-7
Type :
conf
DOI :
10.1109/ICNP.2011.6089047
Filename :
6089047
Link To Document :
بازگشت