LightBox: Full-stack Protected Stateful Middlebox at Lightning Speed
Huayi Duan, Cong Wang, Xingliang Yuan, Yajin Zhou, Qian Wang, Kui Ren
摘要
Running off-site software middleboxes at third-party service providers has been a popular practice. However, routing large volumes of raw traffic, which may carry sensitive information, to a remote site for processing raises severe security concerns. Prior solutions often abstract away important factors pertinent to real-world deployment. In particular, they overlook the significance of metadata protection and stateful processing. Unprotected traffic metadata like low-level headers, size and count, can be exploited to learn supposedly encrypted application contents. Meanwhile, tracking the states of 100,000s of flows concurrently is often indispensable in production-level middleboxes deployed at real networks. We present LightBox, the first system that can drive off-site middleboxes at near-native speed with stateful processing and the most comprehensive protection to date. Built upon commodity trusted hardware, Intel SGX, LightBox is the product of our systematic investigation of how to overcome the inherent limitations of secure enclaves using domain knowledge and customization. First, we introduce an elegant virtual network interface that allows convenient access to fully protected packets at line rate without leaving the enclave, as if from the trusted source network. Second, we provide complete flow state management for efficient stateful processing, by tailoring a set of data structures and algorithms optimized for the highly constrained enclave space. Extensive evaluations demonstrate that LightBox, with all security benefits, can achieve 10Gbps packet I/O, and that with case studies on three stateful middleboxes, it can operate at near-native speed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Zombie: Middleboxes that Don't SnoopCollin Zhang, Zachary DeStefano, Arasu Arun, Joseph Bonneau 等NSDI 2024 · 被引用 26 次
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter 等CCS 2022 · 被引用 19 次
- Don't Yank My Chain: Auditable NF Service ChainingGuyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno 等NSDI 2021 · 被引用 17 次
- Boomerang: Metadata-Private Messaging under Hardware TrustPeipei Jiang, Qian Wang, Jianhao Cheng, Cong Wang 等NSDI 2023 · 被引用 13 次
- Cross-Language AttacksSamuel Mergendahl, Nathan Burow, Hamed OkhraviNDSS 2022
它引用的顶会 Paper6
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels 等CCS 2016 · 被引用 668 次
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang 等CCS 2017 · 被引用 403 次
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih 等NDSS 2017 · 被引用 227 次
- OpenSGX: An Open Platform for SGX ResearchPrerit Jain, Soham Jayesh Desai, Ming-Wei Shih, Taesoo Kim 等NDSS 2016 · 被引用 98 次
相关 Paper
- A Hardware-Software Co-design for Efficient Intra-Enclave IsolationJinyu Gu, Bojun Zhu, Mingyu Li, Wentai Li 等USENIX Security 2022
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 被引用 274 次
- COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXMustakimur Rahman Khandaker, Yueqiang Cheng, Zhi Wang, Tao WeiASPLOS 2020 · 被引用 46 次
- IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX ApplicationsJinhua Cui, Qiao Peng, Yiwen Yao, Ke Ye 等DAC 2025 · 被引用 1 次
