Survey Paper On Efficient Leakage Recovery for IPsec VPNs
Keywords:
IPsec, VPNs, covert channels, performance, trade-offAbstract
Digital exclusive cpa networks (VPNs) are generally progressively more helpful to construct logically separated networks. Even so, existing VPN models and deployments abandoned the challenge involving traffic investigation and covert channels. Consequently, there are several solutions to infer facts through VPN traffic without decrypting the idea. Numerous recommendations are already created to mitigate network covert channels, although past works stayed typically theoretical or maybe triggered prohibitively large padding cost to do business and functionality penalty charges. In this particular cardstock, Researcher: 1) evaluate the particular impression involving covert channels with IPsec; 2) present many improved upon and new strategies for covert station minimization with IPSec; 3) propose and put into practice any system for active functionality trade-offs; and 4) put into practice the style inside Linux IPsec heap and examine it is functionality for unique variations of traffic and minimization guidelines. At only 24% cost to do business, the prototype enforces restricted information-theoretic range about facts seapage.
References
[1] Cohesive Flexible Technologies, Chicago, IL, USA. (2012, Apr.). VPN-Cubed [Online]. Available: http://cohesiveft.com
[2] L. Catuogno, A. Dmitrienko, K. Eriksson, D. Kuhlmann, G. Ramunno, A.-R. Sadeghi, et al., “Trusted virtual domains—Design, implementation and lessons learned,” in Proc. Int. Conf. Trusted Syst., 2009, pp. 156–179.
[3] J. Carapinha, P. Feil, P. Weissmann, S. Thorsteinsson, Ç. Etemo˘glu, O. Ingthórsson, et al., “Network virtualization—Opportunities and challenges for operators,” in Proc. FIS, 2010, pp. 138–147.
[4] B. W. Lampson, “A note on the confinement problem,” Commun. ACM, vol. 16, no. 10, pp. 613–615, 1973.
[5] A Guide to Understanding Covert Channel Analysis of Trusted System, National Computer Security Center, Newton, MA, USA, Nov. 1993.
[6] B. R. Venkatraman and R. E. Newman-Wolfe, “Capacity estimation and auditability of network covert channels,” in Proc. IEEE Symp. Security Privacy, May 1995, pp. 186–198.
[7] M. Liberatore and B. N. Levine, “Inferring the source of encrypted HTTP connections,” in Proc. Conf. CCS, 2006, pp. 255–263.
[8] T. Ristenpart, E. Tromer, H. Shacham, and S. Savage, “Hey, you, get off of my cloud: Exploring information leakage in third-party compute clouds,” in Proc. 16th ACM Conf. CCS, 2009, pp. 199–212.
[9] B. Graham, Y. Zhu, X. Fu, and R. Bettati, “Using covert channels to evaluate the effectiveness of flow confidentiality measures,” in Proc. 11th ICPADS, Jul. 2005, pp. 57–63.
[10] Y. Liu, D. Ghosal, F. Armknecht, A.-R. Sadeghi, S. Schulz, and S. Katzenbeisser, “Hide and seek in time—Robust covert timing channels,” in Proc. Eur. Symp. Res. Comput. Security, 2009, pp. 120–135.
[11] S. Murdoch and S. Lewis, “Embedding covert channels into TCP/IP,” in Information Hiding. New York, NY, USA: Springer-Verlag, 2005.
[12] B. R. Venkatraman and R. E. Newman-Wolfe, “Performance analysis of a method for high level prevention of traffic analysis using measurements from a campus network,” in Proc. 10th Annu. Comput. Security Appl.
Conf., Dec. 1994, pp. 288–297.
[13] J. Millen, “20 years of covert channel modeling and analysis,” in Proc. IEEE Symp. Security Privacy, May 1999, pp. 113–114.
[14] S. Kent and K. Seo, “Security architecture for the internet protocol,” RFC Rep. 4301, Dec. 2005.
[15] K. Ahsan, “Covert channel analysis and data hiding in TCP/IP,” M.S. thesis, Dept. Electr. Comput. Eng., Univ. Toronto, Toronto, ON, Canada, 2002.
[16] D. Kundur and K. Ahsan, “Practical internet steganography: Data hiding in IP,” in Proc. Texas Workshop Security Inf. Syst., 2003, pp. 1–5.
[17] J. P. Degabriele and K. G. Paterson, “On the (in)security of IPsec in MAC-then-encrypt configurations,” in Proc. 17th ACM Conf. CCS, 2010, pp. 493–504.
[18] C. G. Girling, “Covert channels in LAN’s,” IEEE Trans. Softw. Eng., vol. 13, no. 2, pp. 292–296, Feb. 1987.
Downloads
Published
Issue
Section
Categories
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
This work is licensed under a Creative Commons Attribution 4.0 International License.
Under this license, authors retain ownership of the copyright for their articles. By submitting to the International Journal of Advanced Research in Science, Management, and Technology (IJARSMT), authors grant the journal the right of first publication. Users are free to share, copy, and redistribute the material in any medium or format, and to adapt, remix, transform, and build upon the material for any purpose, including commercially, provided that appropriate credit is given to the original author(s) and the journal, a link to the license is provided, and any changes made are indicated.
