论文标题

安全的IP地址分配在云规模上分配

Secure IP Address Allocation at Cloud Scale

论文作者

Pauley, Eric, Domico, Kyle, Hoak, Blaine, Sheatsley, Ryan, Burke, Quinn, Beugin, Yohan, Kirda, Engin, McDaniel, Patrick

论文摘要

公共云需要动态资源分配和共享。但是,对手可以滥用IP地址的动态分配,以采购恶意流量,绕过费率限制系统,甚至捕获针对其他云租户的流量。结果,云提供商及其客户都处于危险之中,并为这些威胁辩护需要对租户行为,对抗策略和云提供商政策进行严格的分析。在本文中,我们通过此类分析为IP地址分配开发了实用的辩护。我们首先根据文献和部署系统的测量来开发云租户部署行为的统计模型。通过此,我们分析了现有和新颖威胁模型下的IP分配策略。为了响应我们提出的更强大的威胁模型,我们设计了IP扫描细分,即即使对手不受云租户数量的限制,也可以保护地址池免受对抗扫描的IP分配策略。通过对综合和现实分配轨迹的经验评估,我们表明IP扫描分割降低了对手快速分配地址的能力,从而保护了地址空间声誉和云租户数据。通过这种方式,我们表明,云IP地址分配的原则分析和实施可以为租户及其用户带来可观的安全收益。

Public clouds necessitate dynamic resource allocation and sharing. However, the dynamic allocation of IP addresses can be abused by adversaries to source malicious traffic, bypass rate limiting systems, and even capture traffic intended for other cloud tenants. As a result, both the cloud provider and their customers are put at risk, and defending against these threats requires a rigorous analysis of tenant behavior, adversarial strategies, and cloud provider policies. In this paper, we develop a practical defense for IP address allocation through such an analysis. We first develop a statistical model of cloud tenant deployment behavior based on literature and measurement of deployed systems. Through this, we analyze IP allocation policies under existing and novel threat models. In response to our stronger proposed threat model, we design IP scan segmentation, an IP allocation policy that protects the address pool against adversarial scanning even when an adversary is not limited by number of cloud tenants. Through empirical evaluation on both synthetic and real-world allocation traces, we show that IP scan segmentation reduces adversaries' ability to rapidly allocate addresses, protecting both address space reputation and cloud tenant data. In this way, we show that principled analysis and implementation of cloud IP address allocation can lead to substantial security gains for tenants and their users.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源