USENIX Security2024Top-tier venue
ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual Trailers
Momen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang, Boubakr Nour, Makan Pourzandi, Mourad Debbabi
Abstract
Network functions virtualization enables tenants to outsource their service function chains (SFCs) to third-party clouds for better agility and cost-effectiveness. However, outsourcing may limit tenants' ability to directly inspect cloud-level deployments to detect attacks on SFC forwarding paths, such as network function bypass or traffic injection. Existing solutions requiring direct cloud access are unsuitable for outsourcing, and adding a cryptographic trailer to every packet may incur significant performance overhead over large flows. In this paper, we propose ChainPatrol, a lightweight solution for tenants to continuously detect and classify cloud-level attacks on SFCs. Our main idea is to "virtualize" cryptographic trailers by encoding them as side-channel watermarks, such that they can be transmitted without adding extra bits to packets. We tackle several key challenges like encoding virtual trailers within the limited side channel capacity, minimizing packet delay, and tolerating unexpected network jitters. We implement our solution on Amazon EC2, and our experiments with real-life data and applications demonstrate that ChainPatrol can achieve a better balance between security (e.g., 100% detection accuracy and 70% classification accuracy) and overhead (e.g., almost zero increased traffic and negligible end-to-end delay) than existing works (e.g., up to 45% overhead reduction compared to a state-of-the-art solution).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on3
- Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsHan Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang et al.AAAI 2023 · 73 citations
- Don't Yank My Chain: Auditable NF Service ChainingGuyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno et al.NSDI 2021 · 17 citations
- EPIC: Every Packet Is Checked in the Data Plane of a Path-Aware InternetMarkus Legner, Tobias Klenze, Marc Wyss, Christoph Sprenger et al.USENIX Security 2020
Related papers
- Inferring Firewall Rules by Cache Side-channel Analysis in Network Function VirtualizationYoungjoo Shin, Dongyoung Koo, Junbeom HurINFOCOM 2020 · 8 citations
- FaaSGuard: An Adaptive Framework for Obfuscating Function Activity States in Serverless ApplicationsXue Leng, Fengming Zhu, Xing Li, Tiantian Zhu et al.INFOCOM 2026 · 1 citation
- Pacer: Comprehensive Network Side-Channel Mitigation in the CloudAastha Mehta, Mohamed Alzayat, Roberta De Viti, Björn B. Brandenburg et al.USENIX Security 2022
- Joint Resource Management and Flow Scheduling for SFC Deployment in Hybrid Edge-and-Cloud NetworkYingling Mao, Xiaojun Shang, Yuanyuan YangINFOCOM 2022 · 52 citations
- DirectFaaS: A Clean-Slate Network Architecture for Efficient Serverless Chain CommunicationsQingyang Zeng, Kaiyu Hou, Xue Leng, Yan ChenWWW 2024 · 5 citations
