SiegeBreaker: An SDN Based Practical Decoy Routing System

Author:

Sharma Piyush Kumar1,Gosain Devashish2,Sagar Himanshu2,Kumar Chaitanya3,Dogra Aneesh2,Naik Vinayak4,Acharya H.B.5,Chakravarty Sambuddho2

Affiliation:

1. Indraprastha Institute of Information Technology (IIIT) Delhi , India

2. IIIT Delhi , India

3. IBM Research , Singapore

4. BITS Pilani , Goa , India

5. RIT , USA

Abstract

Abstract Decoy Routing (DR), a promising approach to censorship circumvention, uses routers (rather than end hosts) as proxy servers. Users of censored networks, who wish to use DR, send specially crafted packets, nominally addressed to an uncensored website. Once safely out of the censored network, the packets encounter a special router (the Decoy Router) which identifies them using a secret handshake, and proxies them to their true destination (a censored site). However, DR has implementation problems: it is infeasible to reprogram routers for the complex operations required. Existing DR solutions fall back on using commodity servers as a Decoy Router. But as servers are not efficient at routing, most web applications show poor performance when accessed over DR. A further concern is that the Decoy Router has to inspect all flows in order to identify the ones that need DR. This may itself be a breach of privacy for other users (who neither require DR nor want to be monitored). In this paper, we present a novel DR system, Siege- Breaker (SB), which solves the aforementioned problems using an SDN-based architecture. Previous proposals involve a single unit which performs all major operations (inspecting all flows, identifying the DR requests and proxying them). In contrast, SB distributes the tasks for DR among three independent modules. (1) The SDN controller identifies DR requests via a covert, privacy preserving scheme, and does not need to inspect all flows. (2) The reconfigurable SDN switch intercepts packets, and forwards them to a secret proxy efficiently. (3) The secret proxy server proxies the client’s traffic to the censored site. Our modular, lightweight design achieves performance comparable to direct TCP downloads, for both in-lab setups, and Internet based tests involving commercial SDN switches.

Publisher

Walter de Gruyter GmbH

Subject

General Medicine

Reference62 articles.

1. [1] Deterlab: Cyber-Defense Technology Experimental Research laboratory. https://www.isi.deterlab.net/index.php.

2. [2] Hp10500 series openflow enabled switches data sheet. http://www.hp.com/hpinfo/newsroom/press_kits/2011/InteropNY2011/HP_10500_Data-Sheet.pdf.

3. [3] Hp3500yl openflow enabled switch data sheet. http://www.curvesales.com/datasheets/switches/Campus-Access/HP-3500-3500-YL-Switch-Series-Datasheet.pdf.

4. [4] Imap library for python. https://docs.python.org/2/library/imaplib.html.

5. [5] List of hp sdn switches. https://techlibrary.hpe.com/ie/en/networking/solutions/technology/sdn/portfolio.aspx#.XjhyRtlS_CI.

Cited by 9 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge;2024 IEEE Symposium on Security and Privacy (SP);2024-05-19

2. PTPerf: On the Performance Evaluation of Tor Pluggable Transports;Proceedings of the 2023 ACM on Internet Measurement Conference;2023-10-24

3. Smart Contract-Based Multi-Stage Service Auction for Refraction Networks;2023 8th International Conference on Computer and Communication Systems (ICCCS);2023-04-21

4. Blind matching algorithm based proxy distribution against internet censorship;IET Communications;2023-02-27

5. The Efficacy and Real-Time Performance of Refraction Networking;Handbook of Real-Time Computing;2022

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3