The Experts below are selected from a list of 201 Experts worldwide ranked by ideXlab platform

Fei Chen - One of the best experts on this subject based on the ideXlab platform.

  • Privacy Preserving Collaborative Enforcement of Firewall Policies in Virtual Private Networks
    2013
    Co-Authors: Alex X. Liu, Fei Chen, Student Member
    Abstract:

    Abstract—The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an Encrypted Tunnel to a VPN server, which, henceforth, allows roaming users to access some resources as if that computer were residing on their home organization’s network. Although VPN technology is very useful, it imposes security threats on the remote network because its firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to nonoverlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-theart, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is three to four orders of magnitude faster than CDCF. Index Terms—Virtual private networks, privacy, network security.

  • privacy preserving collaborative enforcement of firewall policies in virtual private networks
    IEEE Transactions on Parallel and Distributed Systems, 2011
    Co-Authors: Fei Chen
    Abstract:

    The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an Encrypted Tunnel to a VPN server, which, henceforth, allows roaming users to access some resources as if that computer were residing on their home organization's network. Although VPN technology is very useful, it imposes security threats on the remote network because its firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to nonoverlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-the-art, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is three to four orders of magnitude faster than CDCF.

  • IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS 1 Privacy Preserving Collaborative Enforcement of Firewall Policies in Virtual Private Networks 1
    2011
    Co-Authors: Alex X. Liu, Fei Chen
    Abstract:

    Abstract—The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an Encrypted Tunnel to a VPN server, which henceforth allows roaming users to access some resources as if that computer were residing on their home organization’s network. Although VPN technology is very useful, it imposes security threats on the remote network because its firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to non-overlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-the-art, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is three to four orders of magnitude faster than CDCF

  • Collaborative Enforcement of Firewall Policies in Virtual Private Networks
    2010
    Co-Authors: Alex X. Liu, Fei Chen
    Abstract:

    The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an Encrypted Tunnel to a VPN server, which henceforth allows roaming users to access some resources as if that computer is residing on their home organization’s network. Although the VPN technology is very useful, it imposes security threats to the remote network because their firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to non-overlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-theart, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is 552 times faster than CDCF on one party and 5035 times faster than CDCF on the other party

  • PODC - Collaborative enforcement of firewall policies in virtual private networks
    Proceedings of the twenty-seventh ACM symposium on Principles of distributed computing - PODC '08, 2008
    Co-Authors: Alex X. Liu, Fei Chen
    Abstract:

    The widely deployed Virtual Private Network (VPN) technology allows roaming users to build an Encrypted Tunnel to a VPN server, which henceforth allows roaming users to access some resources as if that computer is residing on their home organization's network. Although the VPN technology is very useful, it imposes security threats to the remote network because their firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose VGuard, a framework that allows a policy owner and a request owner to collaboratively determine whether the request satisfies the policy without the policy owner knowing the request and the request owner knowing the policy. We first present an efficient protocol, called Xhash, for oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, without disclosing their numbers to each other. Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of VGuard is to first convert a firewall policy to non-overlapping numerical rules and then use Xhash to check whether a request matches a rule. Comparing with the Cross-Domain Cooperative Firewall (CDCF) framework, which represents the state-of-the-art, VGuard is not only more secure but also orders of magnitude more efficient. On real-life firewall policies, for processing packets, our experimental results show that VGuard is 552 times faster than CDCF on one party and 5035 times faster than CDCF on the other party.

Chris Lonvick - One of the best experts on this subject based on the ideXlab platform.

  • the secure shell ssh connection protocol
    RFC, 2006
    Co-Authors: Tatu Ylonen, Chris Lonvick
    Abstract:

    Secure Shell (SSH) is a protocol for secure remote login and other secure network services over an insecure network. This document describes the SSH Connection Protocol. It provides interactive login sessions, remote execution of commands, forwarded TCP/IP connections, and forwarded X11 connections. All of these channels are multiplexed into a single Encrypted Tunnel. The SSH Connection Protocol has been designed to run on top of the SSH transport layer and user authentication protocols. [STANDARDS-TRACK]

  • the secure shell ssh protocol architecture
    RFC, 2006
    Co-Authors: Tatu Ylonen, Chris Lonvick
    Abstract:

    The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network. This document describes the architecture of the SSH protocol, as well as the notation and terminology used in SSH protocol documents. It also discusses the SSH algorithm naming system that allows local extensions. The SSH protocol consists of three major components: The Transport Layer Protocol provides server authentication, confidentiality, and integrity with perfect forward secrecy. The User Authentication Protocol authenticates the client to the server. The Connection Protocol multiplexes the Encrypted Tunnel into several logical channels. Details of these protocols are described in separate documents. [STANDARDS-TRACK]

Tzongjye Liu - One of the best experts on this subject based on the ideXlab platform.

  • p2p streaming traffic detection in Encrypted Tunnel
    International Symposium on Computing and Networking, 2013
    Co-Authors: Chuanmu Tseng, Lingyao Chao, Tzongjye Liu
    Abstract:

    The evolution of Internet is continually growing, most people use online streaming applications to watch videos. However, some of P2P streaming applications usually occupy the network bandwidth, and the Encrypted Tunnel is usually used to avoid the traffic to be detected. Thus, it is an important issue for ISP to detect the traffic in the Encrypted Tunnel. This paper proposes a novel solution to detect P2P streaming traffic in the Encrypted Tunnel based on the heartbeat signature of the traffic. The solution finds the heartbeat signature by using the plain-text P2P streaming traffic and detects the traffic in the Encrypted Tunnel. The true positive rate and the true negative rate of the proposed solution to detect Funshion traffic can reach 93.67% and 100%, respectively.

  • CANDAR - P2P Streaming Traffic Detection in Encrypted Tunnel
    2013 First International Symposium on Computing and Networking, 2013
    Co-Authors: Chuanmu Tseng, Lingyao Chao, Tzongjye Liu
    Abstract:

    The evolution of Internet is continually growing, most people use online streaming applications to watch videos. However, some of P2P streaming applications usually occupy the network bandwidth, and the Encrypted Tunnel is usually used to avoid the traffic to be detected. Thus, it is an important issue for ISP to detect the traffic in the Encrypted Tunnel. This paper proposes a novel solution to detect P2P streaming traffic in the Encrypted Tunnel based on the heartbeat signature of the traffic. The solution finds the heartbeat signature by using the plain-text P2P streaming traffic and detects the traffic in the Encrypted Tunnel. The true positive rate and the true negative rate of the proposed solution to detect Funshion traffic can reach 93.67% and 100%, respectively.

Tatu Ylonen - One of the best experts on this subject based on the ideXlab platform.

  • the secure shell ssh connection protocol
    RFC, 2006
    Co-Authors: Tatu Ylonen, Chris Lonvick
    Abstract:

    Secure Shell (SSH) is a protocol for secure remote login and other secure network services over an insecure network. This document describes the SSH Connection Protocol. It provides interactive login sessions, remote execution of commands, forwarded TCP/IP connections, and forwarded X11 connections. All of these channels are multiplexed into a single Encrypted Tunnel. The SSH Connection Protocol has been designed to run on top of the SSH transport layer and user authentication protocols. [STANDARDS-TRACK]

  • the secure shell ssh protocol architecture
    RFC, 2006
    Co-Authors: Tatu Ylonen, Chris Lonvick
    Abstract:

    The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network. This document describes the architecture of the SSH protocol, as well as the notation and terminology used in SSH protocol documents. It also discusses the SSH algorithm naming system that allows local extensions. The SSH protocol consists of three major components: The Transport Layer Protocol provides server authentication, confidentiality, and integrity with perfect forward secrecy. The User Authentication Protocol authenticates the client to the server. The Connection Protocol multiplexes the Encrypted Tunnel into several logical channels. Details of these protocols are described in separate documents. [STANDARDS-TRACK]

Subir Biswas - One of the best experts on this subject based on the ideXlab platform.

  • A natural language-inspired multilabel video streaming source identification method based on deep neural networks
    Signal Image and Video Processing, 2021
    Co-Authors: Yan Shi, Dezhi Feng, Yu Cheng, Subir Biswas
    Abstract:

    Existing website fingerprinting techniques are not effective with video streaming traffic when the Encrypted traffic contains multiple streams. This paper presents a deep learning-based source identification method for identifying multiple video sources within a single Encrypted Tunnel. The core contribution is a novel feature inspired by natural language processing (NLP) that allows existing NLP techniques to identify the source. The feature extraction method is described. A large dataset containing video streaming and web traffic is created to verify its effectiveness. Results are obtained by applying several NLP methods to show that the proposed method performs well on both binary and multilabel traffic classification problems. The work proves that the method can overcome the challenges given by mixed-traffic Tunnels.

  • A Natural Language-Inspired Multi-label Video Streaming Traffic Classification Method Based on Deep Neural Networks.
    Signal Image and Video Processing, 2021
    Co-Authors: Yan Shi, Dezhi Feng, Subir Biswas
    Abstract:

    This paper presents a deep-learning based traffic classification method for identifying multiple streaming video sources at the same time within an Encrypted Tunnel. The work defines a novel feature inspired by Natural Language Processing (NLP) that allows existing NLP techniques to help the traffic classification. The feature extraction method is described, and a large dataset containing video streaming and web traffic is created to verify its effectiveness. Results are obtained by applying several NLP methods to show that the proposed method performs well on both binary and multilabel traffic classification problems. We also show the ability to achieve zero-shot learning with the proposed method.

  • Source identification of Encrypted video traffic in the presence of heterogeneous network traffic
    Computer Communications, 2018
    Co-Authors: Yan Shi, Arun Ross, Subir Biswas
    Abstract:

    Abstract This paper uses Traffic Analysis (TA) for identifying sources of Tunneled video streaming traffic. The key idea is to examine Encrypted and Tunneled video streaming traffic at a Soft-Margin Firewall (SMFW) that is located near the streaming client in order to identify undesirable traffic sources and to block or throttle traffic from such sources. The key contribution of the paper is the design and experimental evaluation of a novel two-stage classifier for identifying specific video sources from heterogeneous background traffic within an Encrypted Tunnel. Being able to classify video sources in the presence of such traffic mixture can help the SMFW to successfully obfuscate or block undesired video browsing while allowing a user to receive traffic from legitimate applications running over the same Encrypted Tunnel. Using OpenVPN servers for creating encryption Tunnels, experiments were conducted on a large number of popular video streaming sources with various combinations of feature extraction and data processing techniques to verify the effectiveness of the two-stage classifier. It was experimentally demonstrated that by using the proposed two-stage classifier, it is indeed possible to identify video streaming sources with high accuracy and low false-positive rates in the presence of non-video background traffic within an Encrypted Tunnel.