The Experts below are selected from a list of 5553 Experts worldwide ranked by ideXlab platform
Jun Xu - One of the best experts on this subject based on the ideXlab platform.
-
S-Blocks: Lightweight and Trusted Virtual Security Function with SGX
IEEE Transactions on Cloud Computing, 1Co-Authors: Juan Wang, Hongxin Hu, Bo Zhao, Hongda Li, Wenhui Zhang, Jun XuAbstract:Despite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own Security. To enhance the Security of SFV, a promising approach is to run critical components of off-the-shelf Security software inside SGX enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic Security Function and the unacceptable cost of running them in enclaves. In this work, we propose S-Blocks, an architecture to modularize a virtual Security Function (VSF) and protect its key modules with SGX in an efficient manner. Through systematically decomposing modules of a VSF into related elements, it is easy to put the key modules and elements of the VSF into an enclave. Furthermore, aiming at addressing state consistency and secure migration issues of Security Function scaling, we design a fine-grained state synchronization and migration mechanism to ensure lose-free, order-preserving, and state Security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three main types of virtual Security Functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs.
Zhigang Zhao - One of the best experts on this subject based on the ideXlab platform.
-
Transparently secure smartphone-based social networking
2013 IEEE Wireless Communications and Networking Conference (WCNC), 2013Co-Authors: Yongdong Wu, Zhigang ZhaoAbstract:In social networking, the users' friends are dynamically distributed all over the world and served by many nontrusted and independent providers, thus it is hard to explicitly set-up their public keys with the conventional Public Key Infrastructure so as to provide secure social networking. The present paper aims to build transparently secure channels for social networking. It employs identity-based encryption schemes to enable secure communication with legacy social networking applications based on the users' identities such as telephone numbers. In other words, by stealthily injecting the identity-based Security Function into the existing social networking applications, a user can securely send the messages with the (insecure) applications. The experiments on the instant communication with Android smartphones demonstrate its effectiveness and efficiency.
Frank Kargl - One of the best experts on this subject based on the ideXlab platform.
-
Cooperative home light: assessment of a Security Function for the automotive field
2020Co-Authors: Peter Knapik, Frank Kargl, Jonathan Petit, Elmer SchochAbstract:Crime and feeling of Security are omnipresent and can be influenced by lighting conditions. However, lighting improvements are generally concentrated on street lighting. Meanwhile, a vast variety of new technologies, including innovative lighting systems and connected mobility, are entering into the automotive field. Hence, opportunities are not limited only to provide traffic improvements, entertainment features or driver assistance Functions but also measures to tackle (vehicle-related) crime and to increase feeling of Security. In this paper, we suggest a Security Function, namely the cooperative home light (CHL), which makes use of new technologies and has the potential to tackle crime as well as to increase drivers’ feeling of Security. We also provide an overview of an implementation. However, because of the underlying challenges, the main focus of this paper is to assess the CHL. Therefore, we introduce our three-steps approach consisting of a transfer of related work, a customer survey and results from our proprietary simulation environment in order to assess the CHL.
-
VTC Spring - Electronic Decal: A Security Function Based on V2X Communication
2013 IEEE 77th Vehicular Technology Conference (VTC Spring), 2013Co-Authors: Peter Knapik, Elmer Schoch, Frank KarglAbstract:New technologies such as vehicle-to-X (V2X) communication and advanced driver assistance systems (ADAS) are on the rise. They are mainly used to increase road safety as well as traffic efficiency and to provide customers with infotainment features. However, these new technologies also provide the opportunity to combat vehicle related crime which is present in our society. In this paper, we summarize current measures tackling vehicle related crime and propose a Security Function, namely electronic decal, based on V2X communication to combat vehicle theft. Furthermore, we propose an integration of the electronic decal Functionality into the message format based on the latest standardization progress of the European Telecommunications Standards Institute (ETSI).
-
Electronic decal: A Security Function based on V2X communication
IEEE Vehicular Technology Conference, 2013Co-Authors: Peter Knapik, Elmer Schoch, Frank KarglAbstract:New technologies such as vehicle-to-X (V2X) communication and advanced driver assistance systems (ADAS) are on the rise. They are mainly used to increase road safety as well as traffic efficiency and to provide customers with infotainment features. However, these new technologies also provide the opportunity to combat vehicle related crime which is present in our society. In this paper, we summarize current measures tackling vehicle related crime and propose a Security Function, namely electronic decal, based on V2X communication to combat vehicle theft. Furthermore, we propose an integration of the electronic decal Functionality into the message format based on the latest standardization progress of the European Telecommunications Standards Institute (ETSI).
Paolo Smiraglia - One of the best experts on this subject based on the ideXlab platform.
-
Container-based design of a Virtual Network Security Function
2018 4th IEEE Conference on Network Softwarization and Workshops (NetSoft), 2018Co-Authors: Marco De Benedictis, Antonio Lioy, Paolo SmiragliaAbstract:Modern ICT infrastructures are evolving thanks to the advantages offered by virtualisation in terms of flexibility, scalability, and savings on hardware-related costs. More recently, virtualisation has gained momentum in the Internet Service Providers' infrastructures as well, where Software Defined Networking and Network Function Virtualisation paradigms propose programmability of the network and the softwarisation of proprietary hardware appliances. In this scenario, lightweight virtualisation technologies, such as Linux containers, have a significant role, as they address the needs for scalability, availability and fast deployment to support the software-based network infrastructures. In this paper, we focus on defining a reusable design for a container-based Virtual Network Security Function, by highlighting the peculiarities of its architecture compared to a Virtual Machine-based instance. Moreover, we present a prototype application of this architecture to implement an HTTP reverse proxy with application-layer filtering capabilities, tailored for the NFV Security-as-a-Service scenario. We evaluate the performance of this prototype and compare it to the results of alternative deployments, namely the Virtual Machine and bare-metal solutions. Finally, we evaluate the proposed solution in a load-balancing scenario, for increased throughput and availability.
-
NetSoft - Container-based design of a Virtual Network Security Function
2018 4th IEEE Conference on Network Softwarization and Workshops (NetSoft), 2018Co-Authors: Marco De Benedictis, Antonio Lioy, Paolo SmiragliaAbstract:Modern ICT infrastructures are evolving thanks to the advantages offered by virtualisation in terms of flexibility, scalability, and savings on hardware-related costs. More recently, virtualisation has gained momentum in the Internet Service Providers' infrastructures as well, where Software Defined Networking and Network Function Virtualisation paradigms propose programmability of the network and the softwarisation of proprietary hardware appliances. In this scenario, lightweight virtualisation technologies, such as Linux containers, have a significant role, as they address the needs for scalability, availability and fast deployment to support the software-based network infrastructures. In this paper, we focus on defining a reusable design for a container-based Virtual Network Security Function, by highlighting the peculiarities of its architecture compared to a Virtual Machine-based instance. Moreover, we present a prototype application of this architecture to implement an HTTP reverse proxy with application-layer filtering capabilities, tailored for the NFV Security-as-a-Service scenario. We evaluate the performance of this prototype and compare it to the results of alternative deployments, namely the Virtual Machine and bare-metal solutions. Finally, we evaluate the proposed solution in a load-balancing scenario, for increased throughput and availability.
-
Container-based design of a Virtual Network Security Function
2018 4th IEEE Conference on Network Softwarization and Workshops NetSoft 2018, 2018Co-Authors: Marco De Benedictis, Antonio Lioy, Paolo SmiragliaAbstract:OBJECTIVES: To (i) assess under-reporting of measles-mumps-rubella (MMR) vaccinations to the Australian Childhood Immunisation Register (ACIR); (ii) estimate MMR coverage among five-year-old children and the proportion immune to measles infection; (iii) identify factors related to non-uptake of MMR vaccination.\n\nMETHODS: We analysed ACIR data for a birth cohort of approximately 64,000 children aged five years. The parents of a sample of 506 children with no ACIR record for the second MMR vaccination (MMR2), due at four years of age, were interviewed by telephone to assess under-reporting to the ACIR and reasons for non-uptake of MMR vaccination.\n\nRESULTS: Parents reported that 22% (n = 111) of the surveyed 506 children had received MMR2 before their fifth birthday, and 42% (n = 214) by approximately 5.5 years of age. After correcting for this level of under-reporting to the ACIR, MMR2 coverage for the entire cohort at five years of age was 52.9% (95% CI 52.3-53.4), and increased to 84.1% (95% CI 83.4-84.8) by approximately 5.5 years of age. This was 4.3% and 8.2%, respectively, higher than ACIR coverage estimates at the two ages. Based on the corrected MMR coverage estimates, 93% of the cohort was immune to measles due to vaccination. The most common parent-reported reason for incomplete vaccination was lack of knowledge about the MMR vaccination schedule.\n\nCONCLUSIONS: Measles elimination in Australia will require continued effort in vaccination coverage and timeliness among pre-school children. School-entry requirements are important for MMR2 uptake. Strategies are needed to improve reporting to the ACIR for more accurate measurement of coverage.
Juan Wang - One of the best experts on this subject based on the ideXlab platform.
-
S-Blocks: Lightweight and Trusted Virtual Security Function with SGX
IEEE Transactions on Cloud Computing, 1Co-Authors: Juan Wang, Hongxin Hu, Bo Zhao, Hongda Li, Wenhui Zhang, Jun XuAbstract:Despite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own Security. To enhance the Security of SFV, a promising approach is to run critical components of off-the-shelf Security software inside SGX enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic Security Function and the unacceptable cost of running them in enclaves. In this work, we propose S-Blocks, an architecture to modularize a virtual Security Function (VSF) and protect its key modules with SGX in an efficient manner. Through systematically decomposing modules of a VSF into related elements, it is easy to put the key modules and elements of the VSF into an enclave. Furthermore, aiming at addressing state consistency and secure migration issues of Security Function scaling, we design a fine-grained state synchronization and migration mechanism to ensure lose-free, order-preserving, and state Security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three main types of virtual Security Functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs.