TY - GEN
T1 - Internet security liberated via software defined exchanges
AU - Wang, Kuang Ching
AU - Oakley, Jonathan
AU - Brooks, Richard R.
AU - Yu, Lu
AU - Barrineau, Geddings
AU - Wang, Qing
N1 - Publisher Copyright: © 2018 Association for Computing Machinery.
PY - 2018/3/14
Y1 - 2018/3/14
N2 - With software defined networking and network function virtualization technologies, networks can be programmed to have customized processing and paths for different traffic at manageable costs and for massive numbers of applications. Now, picture a future Internet where each entity - a person, an organization, or an autonomous system - has the ability to choose how traffic in their respective network sessions is routed and processed between itself and its counterparts. The network is, essentially, liberated from today’s homogeneous IP-based routing and limited connection options. To realize such a network paradigm, we propose a software defined exchange architecture that can provide the needed network pro-grammability, session-level customization, and scale. We present a case study for traffic-analysis-resistant communication among individuals, campuses, or web services, where IP addresses no longer need to have a one-to-one correspondence with service providers.
AB - With software defined networking and network function virtualization technologies, networks can be programmed to have customized processing and paths for different traffic at manageable costs and for massive numbers of applications. Now, picture a future Internet where each entity - a person, an organization, or an autonomous system - has the ability to choose how traffic in their respective network sessions is routed and processed between itself and its counterparts. The network is, essentially, liberated from today’s homogeneous IP-based routing and limited connection options. To realize such a network paradigm, we propose a software defined exchange architecture that can provide the needed network pro-grammability, session-level customization, and scale. We present a case study for traffic-analysis-resistant communication among individuals, campuses, or web services, where IP addresses no longer need to have a one-to-one correspondence with service providers.
KW - Censorship Circumvention
KW - Cloud
KW - GENI
KW - Internet Architecture
KW - PEERING
KW - SDN
KW - SDX
KW - Wide Area Network
UR - https://www.scopus.com/pages/publications/85052014074
U2 - 10.1145/3180465.3180475
DO - 10.1145/3180465.3180475
M3 - Conference contribution
T3 - SDN-NFVSec 2018 - Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, Co-located with CODASPY 2018
SP - 19
EP - 22
BT - SDN-NFVSec 2018 - Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, Co-located with CODASPY 2018
PB - Association for Computing Machinery
T2 - 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFVSec 2018, Co-located with CODASPY 2018
Y2 - 21 March 2018 through 21 March 2018
ER -