{"title":"基于IPSec的NetFlow抓包系统加密仿真","authors":"A. J. Ghazali, W. Al-Nuaimy, A. Nandi","doi":"10.1109/CODEC.2012.6509361","DOIUrl":null,"url":null,"abstract":"This paper investigates the effectiveness of IPSec as encryption tools in securing NetFlow packets through an encapsulated channel in a simulated network traffic model. NetFlow's flow recording is one of the most serious threats that has broad significance in NetFlow's flow recording technology. By securing the NetFlow, the administrator could enforce a privacy policy on the data that is recorded. We employ IPSec as encryption tool that encapsulates the flow and turns it into a secured channel. Furthermore, we demonstrate that the CPU and memory utilization during the process will not have a big impact on machine's performance. Simulation results show that NetFlow's flow data are successfully recorded and encrypted by IPSec. It is found that this process has not consumed more memory which only differs by 0.2% from normal operation and that the CPU performance is only increased by 6.5%.","PeriodicalId":399616,"journal":{"name":"2012 5th International Conference on Computers and Devices for Communication (CODEC)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Simulation of the encryption of NetFlow packet capturing system using IPSec\",\"authors\":\"A. J. Ghazali, W. Al-Nuaimy, A. Nandi\",\"doi\":\"10.1109/CODEC.2012.6509361\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper investigates the effectiveness of IPSec as encryption tools in securing NetFlow packets through an encapsulated channel in a simulated network traffic model. NetFlow's flow recording is one of the most serious threats that has broad significance in NetFlow's flow recording technology. By securing the NetFlow, the administrator could enforce a privacy policy on the data that is recorded. We employ IPSec as encryption tool that encapsulates the flow and turns it into a secured channel. Furthermore, we demonstrate that the CPU and memory utilization during the process will not have a big impact on machine's performance. Simulation results show that NetFlow's flow data are successfully recorded and encrypted by IPSec. It is found that this process has not consumed more memory which only differs by 0.2% from normal operation and that the CPU performance is only increased by 6.5%.\",\"PeriodicalId\":399616,\"journal\":{\"name\":\"2012 5th International Conference on Computers and Devices for Communication (CODEC)\",\"volume\":\"22 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2012 5th International Conference on Computers and Devices for Communication (CODEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CODEC.2012.6509361\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 5th International Conference on Computers and Devices for Communication (CODEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CODEC.2012.6509361","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Simulation of the encryption of NetFlow packet capturing system using IPSec
This paper investigates the effectiveness of IPSec as encryption tools in securing NetFlow packets through an encapsulated channel in a simulated network traffic model. NetFlow's flow recording is one of the most serious threats that has broad significance in NetFlow's flow recording technology. By securing the NetFlow, the administrator could enforce a privacy policy on the data that is recorded. We employ IPSec as encryption tool that encapsulates the flow and turns it into a secured channel. Furthermore, we demonstrate that the CPU and memory utilization during the process will not have a big impact on machine's performance. Simulation results show that NetFlow's flow data are successfully recorded and encrypted by IPSec. It is found that this process has not consumed more memory which only differs by 0.2% from normal operation and that the CPU performance is only increased by 6.5%.