Efficient Anonymous Communication in SDN-Based Data Center Networks

被引:19
|
作者
Zhu, Tingwei [1 ]
Feng, Dan [1 ]
Wang, Fang [1 ,2 ]
Hua, Yu [1 ]
Shi, Qingyu [1 ]
Liu, Jiahao [1 ]
Cheng, Yongli [3 ]
Wan, Yong [4 ]
机构
[1] Huazhong Univ Sci & Technol, Key Lab Informat Storage Syst, Sch Comp Sci & Technol, Minist Educ China,Wuhan Natl Lab Optoelect, Wuhan 430074, Hubei, Peoples R China
[2] Shenzhen Huazhong Univ Sci & Technol, Res Inst, Shenzhen 518000, Peoples R China
[3] Fuzhou Univ, Coll Math & Comp Sci, Fuzhou 350108, Fujian, Peoples R China
[4] Jingchu Univ Technol, Comp Engn Coll, Jingmen 448000, Peoples R China
关键词
Anonymity; data center; software-defined networking; in-network anonymous communication; distributed file system; PROTOCOL;
D O I
10.1109/TNET.2017.2751616
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the rapid growth of application migration, the anonymity in data center networks becomes important in breaking attack chains and guaranteeing user privacy. However, existing anonymity systems are designed for the Internet environment, which suffer from high computational and network resource consumption and deliver low performance, thus failing to be directly deployed in data centers. In order to address this problem, this paper proposes an efficient and easily deployed anonymity scheme for software defined networking-based data centers, called mimic channel (MIC). The main idea behind MIC is to conceal the communication participants by modifying the source/destination addresses, such as media access control (MAC) and Internet protocol (IP) address at switch nodes, so as to achieve anonymity. Compared with the traditional overlay-based approaches, our in-network scheme has shorter transmission paths and less intermediate operations, thus achieving higher performance with less overhead. We also propose a collision avoidance mechanism to ensure the correctness of routing, and three mechanisms to enhance the traffic-analysis resistance. To enhance the practicality, we further propose solutions to enable MIC co-existing with some MIC-incompatible systems, such as packet analysis systems, intrusion detection systems, and firewall systems. Our security analysis demonstrates that MIC ensures unlinkability and improves traffic-analysis resistance. Our experiments show that MIC has extremely low overhead compared with the base-line transmission control protocol (TCP) (or secure sockets layer (SSL)), e.g., less than 1% overhead in terms of throughput. Experiments on MIC-based distributed file system show the applicability and efficiency of MIC.
引用
收藏
页码:3767 / 3780
页数:14
相关论文
共 50 条
  • [1] A Management Model for SDN-based Data Center Networks
    Xu, Yifei
    Yan, Yue
    Dai, Zhuyun
    Wang, Xiaolin
    [J]. 2014 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2014, : 113 - +
  • [2] Multipath Routing in SDN-based Data Center Networks
    Lei, Yi-Chih
    Wang, Kuochen
    Hsu, Yi-Huai
    [J]. 2015 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2015, : 365 - 369
  • [3] SDN-Based ECMP Algorithm for Data Center Networks
    Zhang, Hailong
    Guo, Xiao
    Yan, Jinyao
    Liu, Bo
    Shuai, Qianjun
    [J]. 2014 IEEE COMPUTING, COMMUNICATIONS AND IT APPLICATIONS CONFERENCE (COMCOMAP), 2014, : 13 - 18
  • [4] Dynamic Load Balancing in SDN-Based Data Center Networks
    Zakia, Umme
    Ben Yedder, Hanene
    [J]. 2017 8TH IEEE ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2017, : 242 - 247
  • [5] An Improved SDN-Based Fabric for Flexible Data Center Networks
    Hou, Wei
    Shi, Linda
    Wang, Yingzhe
    Wang, Fan
    Lyu, Hui
    St-Hilaire, Marc
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016, : 432 - 436
  • [6] An SDN-Based Slow Start Algorithm for Data Center Networks
    Hu Yao
    Wu Muqing
    Ling Shen
    [J]. PROCEEDINGS OF 2017 IEEE 2ND INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2017, : 687 - 691
  • [7] An SDN-Based Fabric For Flexible Data-Center Networks
    Chen, Longbin
    Qiu, Meikang
    Xiong, Jian
    [J]. 2015 IEEE 2ND INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2015, : 121 - 126
  • [8] SDN-based TCP Congestion Control in Data Center Networks
    Lu, Yifei
    Zhu, Shuhong
    [J]. 2015 IEEE 34TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2015,
  • [9] Overhead reduction scheme for SDN-based Data Center Networks
    Pranata, Alif Akbar
    Jun, Tae Soo
    Kim, Dong Seong
    [J]. COMPUTER STANDARDS & INTERFACES, 2019, 63 : 1 - 15
  • [10] Horizon: a QoS management framework for SDN-based data center networks
    Junjie Pang
    Gaochao Xu
    Xiaodong Fu
    Kuo Zhao
    [J]. Annals of Telecommunications, 2017, 72 : 597 - 605