Don't Yank My Chain: Auditable NF Service Chaining
Guyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno, Vyas Sekar, Justine Sherry
Abstract
Auditing is a crucial component of network security practices in organizations with sensitive information, such as banks and hospitals. Unfortunately, network function virtualization (NFV) is viewed as incompatible with auditing practices which verify that security functions operate correctly. In this paper, we bring the benefits of NFV to security-sensitive environments with the design and implementation of AuditBox.
AuditBox not only makes NFV compatible with auditing, but also provides stronger guarantees than traditional auditing procedures. In traditional auditing, administrators test the system for correctness on a schedule, e.g., once per month. In contrast, AuditBox continuously self-monitors for correct behavior, proving runtime guarantees that the system remains in compliance with policy goals. Furthermore, AuditBox remains compatible with traditional auditing practices by providing sampled logs which still allow auditors to inspect system behavior manually. AuditBox achieves its goals by combining trusted execution environments with a lightweight verified routing protocol (VRP). Despite the complexity of routing policies for service-function chains relative to traditional routing, Audit-Box's protocol introduces 72-80% fewer bytes of overhead per packet (in a 5-hop service chain) and provides 61-67% higher goodput than prior work on VRPs designed for the Internet.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 772b19fc-291d-4cee-a0c7-4a5136b64230Cited by top-tier papers3
- LemonNFV: Consolidating Heterogeneous Network Functions at Line SpeedHao Li, Yihan Dang, Guangda Sun, Guyue Liu et al.NSDI 2023 · 21 citations
- TrustSketch: Trustworthy Sketch-based Telemetry on Cloud HostsZhuo Cheng, Maria Apostolaki, Zaoxing Liu, Vyas SekarNDSS 2024
- ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual TrailersMomen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang et al.USENIX Security 2024
Builds on8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- EverCrypt: A Fast, Verified, Cross-Platform Cryptographic ProviderJonathan Protzenko, Bryan Parno, Aymeric Fromherz, Chris Hawblitzel et al.S&P 2020 · 114 citations
- LightBox: Full-stack Protected Stateful Middlebox at Lightning SpeedHuayi Duan, Cong Wang, Xingliang Yuan, Yajin Zhou et al.CCS 2019 · 88 citations
Related papers
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran et al.INFOCOM 2020 · 13 citations
- DPUaudit: DPU-assisted Pull-based Architecture for Near-Zero Cost System AuditingPeng Jiang, Hanlin Jiang, Ruizhe Huang, Hanwen Lei et al.HPCA 2025 · 3 citations
- HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud PlatformsRenpeng Zhang, Kai Shen, Peng Jiang, Ding Li et al.USENIX Security 2026
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 32 citations
