Tags:anonymization, IPv6, network traffic and traffic measurement
Abstract:
Aiming at the problem of trace anonymization performance of backbone networks, we propose a real-time anonymization method for the IP address of backbone network packets based on flow tables (named AFT-Anon). This method can dynamically build an anonymous flow table based on the captured data packets. The first data packet of a network flow is encrypted according to a specific encryption algorithm, and the encrypted fields are stored in the flow record. Subsequent data packets can obtain the encrypted fields by searching flow records and replace the corresponding fields of the original data packets to achieve anonymization of data packets. Based on the proposed method, a high-speed network anonymization system is developed and deployed on the backbone link of an Internet service provider network. Experimental results show that the proposed method can improve the anonymization performance by more than 20 times, compared with the existing methods such as Crypto-Pan, and it can meet the requirements for online anonymization of 10G link.
AFT-Anon: a Scaling Method for Online Trace Anonymization Based on Anonymous Flow Tables