Skip to main navigation Skip to search Skip to main content

Challenges towards protecting VNF with SGX

  • Juan Wang
  • , Chengyang Fan
  • , Shirong Hao
  • , Jie Wang
  • , Yi Li
  • , Lin Han
  • , Zhi Hong
  • , Hongxin Hu
  • Wuhan University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

16 Scopus citations

Abstract

Network Function Virtualization (NFV) is an emerging technology to implement network functions in software, which reduces equipment costs (CAPEX) and operational cost (OPEX) through decoupling network functions from network dedicated devices and deploying them on high-volume standard servers and running as virtual instances. However, due to running in a shared and open environment and lacking the protection of proprietary hardware, virtual network functions (VNFs) face more security threats than traditional network functions. Hence, it is crucial to build a trusted execution environment to protect VNFs. In this paper, we first analyze the challenges for VNF security protection. We then propose a lightweight and trusted execution environment for securing VNFs based on SGX and Click. To demonstrate the feasibility of our approach, we implement a DDoS defense function on top of our environment and conduct paramilitary evaluations. Our evaluation results show that our system only introduces manageable performance overhead for protecting VNFs.

Original languageEnglish
Title of host publicationSDN-NFVSec 2018 - Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, Co-located with CODASPY 2018
PublisherAssociation for Computing Machinery, Inc
Pages39-42
Number of pages4
ISBN (Electronic)9781450356350
DOIs
StatePublished - Mar 14 2018
Event2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFVSec 2018 - Tempe, United States
Duration: Mar 21 2018 → …

Publication series

NameSDN-NFVSec 2018 - Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, Co-located with CODASPY 2018
Volume2018-January

Conference

Conference2018 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFVSec 2018
Country/TerritoryUnited States
CityTempe
Period03/21/18 → …

Keywords

  • Click
  • Intel SGX
  • NFV
  • Trust
  • VNF

Fingerprint

Dive into the research topics of 'Challenges towards protecting VNF with SGX'. Together they form a unique fingerprint.

Cite this