Sec-ALG: An Open-source Application Layer Gateway for Secure Access to Private Networks

被引:1
|
作者
Riaz, Maria [1 ]
Tilli, Juha-Matti [1 ]
Kantola, Raimo [1 ]
机构
[1] Aalto Univ, Dept Commun & Networking, Espoo, Finland
关键词
D O I
10.1109/icccn49398.2020.9209718
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Middleboxes such as Network Address Translators (NATs), proxy servers or Application Layer Gateways (ALGs) provide remote access to end-hosts in the private address space. The middleboxes offer proprietary solutions and encrypted traffic poses a challenge when middleboxes employ packet payload inspection techniques for connection establishment. Session key sharing and decryption followed by re-encryption of the traffic, for correctly routing to the private host, increases the connection latency and also poses a higher threat in case of traffic interception by a malicious third-party. In this paper, we present a novel open-source ALG, called Sec-ALG, for providing secure end-to-end communication to the web servers situated in the private address space. Sec-ALG relies on the technique of light Deep Packet Inspection (DPI) for protocol detection and session establishment using a novel parser-lexer generator called YaLe. The proposed approach offers increased security by maintaining end-to-end encryption for an HTTPS connection. Our experimental analysis demonstrates that Sec-ALG reduces the HTTPS connection latency in comparison to the NGINX reverse proxy using a 24-core host machine. Moreover, Sec-ALG handles requests at a three-fold increased rate than NGINX proxy when tested with 100 concurrent connections. The ALG can be used either as a standalone solution or a component of the Realm Gateway, that is a generic interworking solution between public and private networks. The presented work is part of an extensive ongoing research at Aalto University focusing on embedding policy based trust into the network.
引用
收藏
页数:11
相关论文
共 9 条
  • [1] SecMGW - An open-source enterprise gateway for secure e-mail
    Straub, T
    Fleck, M
    Growe, R
    Lenze, O
    [J]. ISSE 2004 - SECURING ELECTRONIC BUSINESS PROCESSES, 2004, : 237 - 249
  • [2] Building a gateway with open source software for secure-DICOM communication over insecure networks
    Emmel, D
    Ricke, J
    Stohlmann, L
    Haderer, A
    Felix, R
    [J]. MEDICAL IMAGING 2002: PACS AND INTEGRATED MEDICAL INFORMATION SYSTEMS: DESIGN AND EVALUATION, 2002, 4685 : 243 - 251
  • [3] Application of Open-Source Deep Neural Networks for Object Detection in Industrial Environments
    Poss, Christian
    Ibragimov, Olimjon
    Indreswaran, Anoshan
    Gutsche, Nils
    Irrenhauser, Thomas
    Prueglmeier, Marco
    Goehring, Daniel
    [J]. 2018 17TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2018, : 231 - 236
  • [4] GNPy: an open source application for physical layer aware open optical networks
    Ferrari, Alessio
    Filer, Mark
    Balasubramanian, Karthikeyan
    Yin, Yawei
    Le Rouzic, Esther
    Kundrat, Jan
    Grammel, Gert
    Galimberti, Gabriele
    Curri, Vittorio
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2020, 12 (06) : C31 - C40
  • [5] Open-Source Enabled Beyond 5G Private Mobile Networks: From Concept to Prototype
    Mihai, Razvan
    Craciunescu, Razvan
    Martian, Alexandru
    Li, Frank Y.
    Patachia, Cristian
    Vochin, Marius-Constantin
    [J]. 2022 25TH INTERNATIONAL SYMPOSIUM ON WIRELESS PERSONAL MULTIMEDIA COMMUNICATIONS (WPMC), 2022,
  • [6] A Cloud Based System to Sense Security Vulnerabilities of Web Application in Open-Source Private Cloud IAAS
    Kankhare, Deepak Dattatray
    Manjrekar, A. A.
    [J]. 2016 INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2016, : 252 - 255
  • [7] Resiliency in Open-Source Solutions for Disaggregated 5G Cloud Radio Access and Transport Networks
    Ramanathan, Shunmugapriya
    Kondepu, Koteswararao
    Fumagalli, Andrea
    [J]. 2022 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2022, : 124 - 129
  • [8] Open-source automatic extraction of Urban Green Space: Application to assessing improvement in green space access
    Estacio, Ian
    Roman-Palacios, Cristian
    Hoover, Joseph
    Li, Xiaojiang
    Lim, Chris
    [J]. ISPRS ANNALS OF THE PHOTOGRAMMETRY, REMOTE SENSING AND SPATIAL INFORMATION SCIENCES: VOLUME X-2-2024, 2024, : 65 - 72
  • [9] The AirSensor open-source R-package and DataViewer web application for interpreting community data collected by low-cost sensor networks
    Feenstra, Brandon
    Collier-Oxandale, Ashley
    Papapostolou, Vasileios
    Cocker, David
    Polidori, Andrea
    [J]. ENVIRONMENTAL MODELLING & SOFTWARE, 2020, 134 (134)