Detection of Anomalous e2e Encrypted Function Invocation in FaaS using Zero-Knowledge Proofs

被引:0
|
作者
Andreotti, Davide [1 ]
Verticale, Giacomo [1 ]
机构
[1] Politecn Milan, Dept Elect Informat & Bioengn, Milan, Italy
关键词
Zero-Knowledge Proofs; Function-as-a-Service; Middlebox; Moving Target Defense;
D O I
10.1109/NetSoft60951.2024.10588930
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Function-as-a-Service providers manage security devices that are shared among multiple tenants. It is undesirable to give them access to cleartext HTTP requests to perform tasks such as traffic inspection. The recent Zero-Knowledge Middlebox (ZKMB) can be used to enforce network policies on TLS traffic without revealing any information on the content to the policy verifier. In this paper, we describe a ZKMB implementation and a policy designed to check whether the HTTPS function invocations by the clients follow a legitimate pattern. We also present and compare two strategies to distribute allowed patterns, introducing a Moving-Target Defense approach for the function URI randomization, which shows a good tradeoff between detection effectiveness and confidentiality. Performance assessment in our prototype implementation shows that the ZK algorithms are not yet suitable for real-time execution, but current research interest in this technology is expected to narrow this gap.
引用
收藏
页码:175 / 179
页数:5
相关论文
共 5 条
  • [1] Better privacy and security in e-commerce: Using elliptic curve-based zero-knowledge proofs
    Almuhammadi, S
    Sui, NT
    McLeod, D
    CEC 2004: IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE TECHNOLOGY, PROCEEDINGS, 2004, : 299 - 302
  • [2] Streaming Intended Query Detection using E2E Modeling for Continued Conversation
    Chang, Shuo-yiin
    Prakash, Guru
    Wu, Zelin
    Liang, Qiao
    Sainath, Tara N.
    Li, Bo
    Stambler, Adam
    Upadhyay, Shyam
    Faruqui, Manaal
    Strohman, Trevor
    INTERSPEECH 2022, 2022, : 1826 - 1830
  • [3] A Blockchain-Based E-Participation Framework Utilizing Zero-Knowledge Proofs With Guaranteed Sampling and Differential Reward Mechanisms
    Seo, Jungwon
    Lee, Juhui
    Joo, Yunjae
    Lee, Kangho
    Sugumaran, Vijayan
    Park, Sooyong
    IEEE ACCESS, 2025, 13 : 25752 - 25764
  • [4] HubNet: An E2E Model for Wheel Hub Text Detection and Recognition Using Global and Local Features
    Zeng, Yue
    Meng, Cai
    SENSORS, 2024, 24 (19)
  • [5] Smart Contract-Based E-Voting System Using Homomorphic Encryption and Zero-Knowledge Proof
    Wu, Yuxiao
    Kasahara, Shoji
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2023 SATELLITE WORKSHOPS, ADSC 2023, AIBLOCK 2023, AIHWS 2023, AIOTS 2023, CIMSS 2023, CLOUD S&P 2023, SCI 2023, SECMT 2023, SIMLA 2023, 2023, 13907 : 67 - 83