Please use this identifier to cite or link to this item:
Title: An SFC-enabled approach for processing SSL/TLS encrypted traffic in future enterprise networks
Author: Cunha, Vítor A.
Carvalho, Marcio B. de
Corujo, Daniel
Barraca, João P.
Gomes, Diogo
Schaeffer-Filho, Alberto E.
Santos, Carlos R. P. dos
Granville, Lisandro Z.
Aguiar, Rui L.
Issue Date: Jun-2018
Publisher: IEEE
Abstract: In this paper, we propose an architecture based on NFV and SDN which allows to balance traffic analysis techniques using a Classifier. It steers flows to the appropriate Service Function Chaining (to open traffic or not) according to network requirements (such as, effectiveness, flexibility, scalability, performance, and privacy). The SSL/TLS traffic processing is carried-out by the centerpiece of this work, the SFC-enabled MITM. A Proof-of-Concept was conducted (focusing on our SFC-enabled MITM) which showed that functionalities lost due to encryption (Content Optimization, Caching, Network Anti-virus, and Content Filter) were recovered when processing opened traffic within its Service Function Chains. We also evaluated its impact on performance. The results show that cipher suite overhead plays a role but can be mitigated, the Classifier can alleviate the performance overhead of different traffic analysis techniques, network functions have lower impact to performance, and Service Function Chaining length influences page load time.
Peer review: yes
DOI: 10.1109/ISCC.2018.8538564
ISBN: 978-153866951-8
ISSN: 15301346
Appears in Collections:DETI - Capítulo de livro
IT - Capítulo de livro

Files in This Item:
File Description SizeFormat 
1570434804.pdf204.67 kBAdobe PDFView/Open

Formato BibTex MendeleyEndnote Degois 

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.