A Step Towards On-Path Security Function Outsourcing
Jehyun Lee, Min Suk Kang, Dinil Mon Divakaran, Phyo May Thet, Videet, Singhai, Jun Seung You

TL;DR
This paper introduces Opsec, a practical end-to-end protocol enabling on-path security function outsourcing by automatically discovering transit networks and requesting security services, compatible with current Internet protocols.
Contribution
It presents Opsec, a novel protocol for practical on-path security outsourcing that works within existing Internet infrastructure and protocols.
Findings
Opsec can discover transit ISPs automatically.
It allows users to specify security functions easily.
Implementation shows compatibility with current web protocols.
Abstract
Security function outsourcing has witnessed both research and deployment in the recent years. While most existing services take a straight-forward approach of cloud hosting, on-path transit networks (such as ISPs) are increasingly more interested in offering outsourced security services to end users. Recent proposals (such as SafeBricks and mbTLS) have made it possible to outsource sensitive security applications to untrusted, arbitrary networks, rendering on-path security function outsourcing more promising than ever. However, to provide on-path security function outsourcing, there is one crucial component that is still missing -- a practical end-to-end network protocol. Thus, the discovery and orchestration of multiple capable and willing transit networks for user-requested security functions have only been assumed in many studies without any practical solutions. In this work, we…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
