본문

서브메뉴

Revising System Premises for a Secure and Private Web
Revising System Premises for a Secure and Private Web
Revising System Premises for a Secure and Private Web

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20250211151352
ISBN  
9798382760766
DDC  
004
저자명  
Xiao, Yunming.
서명/저자  
Revising System Premises for a Secure and Private Web
발행사항  
[Sl] : Northwestern University, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
202 p
주기사항  
Source: Dissertations Abstracts International, Volume: 85-11, Section: A.
주기사항  
Advisor: Kuzmanovic, Aleksandar.
학위논문주기  
Thesis (Ph.D.)--Northwestern University, 2024.
초록/해제  
요약As residential bandwidth continues to grow and people become increasingly dependent on the Internet, previously overlooked security and privacy issues have become severe threats to Internet users, raising public concerns. These threats are numerous and far-reaching, spanning across various network or system layers, as well as different applications and services. Despite the considerable efforts made, the current situation is still far from ideal, mainly because of the continuously evolving security and privacy demands, as well as the rapid development of counter measures.This thesis aims to examine the security and privacy vulnerabilities in the current Web components and present appropriate solutions to address them. My approach is to develop practical cutting-edge network systems that enhance security and privacy without compromising on efficiency. To achieve this objective, I undertake comprehensive evaluations to gain insights into the current systems, and suggest enhancements through revising the key system premises that contribute to the vulnerabilities. Such revisions facilitate the mitigation of vulnerabilities and allow the incorporation of new system pieces, e.g., advanced cryptographic tools. The resulting system should also provide satisfactory performance and be feasible to be deployed today.In this thesis, I begin by examining one general concept for securing any network system - the virtual private network (VPN). Specifically, I concentrate on decentralized VPN (DVPN), a recent system revision proposal that improves user privacy by distributing VPN proxies to multiple parties, making it challenging for anyone to retrieve information about users and connections. Nonetheless, my analysis reveals that DVPN fails to provide adequate security and privacy guarantees due to the reliance on trust placed in the proxies.Unfortunately, relieving such trust dependencies in a proxy-based system proves to be a formidable task. Hence, I pivot to directly enhancing the specific Internet services and applications themselves. My first target is the domain name service (DNS), a fundamental Internet service behind almost any wild-area network requests. Through careful scrutinization of existing proposals, I find that the presence of recursive resolvers is the key system premise that contribute to the current DNS privacy vulnerabilities. DNS privacy can be substantially improved by having the recursive resolvers operate in blind, i.e., answering the queries without knowing their contents. While this sounds counter-intuitive, it can actually be realized through advanced cryptography tools named private information retrieval (PIR). Following this direction, I build PDNS, an efficient and practical DNS system based on PIR. Thorough evaluations demonstrate that PDNS achieves acceptable performance as of today and offers better privacy preservation than any state-of-the-art proposals.PDNS cannot safeguard the interconnected and multi-layered Internet alone. Indeed, user privacy exposure at one component negates protective measures at other components. With this in mind, I proceed to investigate another vital Internet component, the Hypertext Transfer Protocol (HTTP) -- the bedrock of the Web -- where I identify an instance of such a privacy violation. Specifically, Web providers are harvesting user information through HTTP cookies. The root cause is that current cookies are semantically oblivious, i.e., they carry personally identifiable information (PII) but lack useful information for analytics. To solve this issue, I revise the system premises and propose semantic cookies -- cookies discarding any PII. Evaluations show that semantic cookies not only patch up privacy leakage in HTTP requests but also accelerate cookie analytics by exploiting edge infrastructures, providing incentives for adoption. This exemplifies my system design philosophy of achieving balance among performance, security/privacy guarantees, and practicality.
일반주제명  
Computer science
일반주제명  
Web studies
일반주제명  
Information technology
키워드  
Private information retrieval
키워드  
Web components
키워드  
Virtual private network
키워드  
Personally identifiable information
기타저자  
Northwestern University Computer Science
기본자료저록  
Dissertations Abstracts International. 85-11A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017161409
■00520250211151352
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798382760766
■035    ▼a(MiAaPQ)AAI31243408
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼aXiao,  Yunming.▼0(orcid)0000-0002-4913-4881
■24510▼aRevising  System  Premises  for  a  Secure  and  Private  Web
■260    ▼a[Sl]▼bNorthwestern  University▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a202  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  85-11,  Section:  A.
■500    ▼aAdvisor:  Kuzmanovic,  Aleksandar.
■5021  ▼aThesis  (Ph.D.)--Northwestern  University,  2024.
■520    ▼aAs  residential  bandwidth  continues  to  grow  and  people  become  increasingly  dependent  on  the  Internet,  previously  overlooked  security  and  privacy  issues  have  become  severe  threats  to  Internet  users,  raising  public  concerns.  These  threats  are  numerous  and  far-reaching,  spanning  across  various  network  or  system  layers,  as  well  as  different  applications  and  services.  Despite  the  considerable  efforts  made,  the  current  situation  is  still  far  from  ideal,  mainly  because  of  the  continuously  evolving  security  and  privacy  demands,  as  well  as  the  rapid  development  of  counter  measures.This  thesis  aims  to  examine  the  security  and  privacy  vulnerabilities  in  the  current  Web  components  and  present  appropriate  solutions  to  address  them.  My  approach  is  to  develop  practical  cutting-edge  network  systems  that  enhance  security  and  privacy  without  compromising  on  efficiency.  To  achieve  this  objective,  I  undertake  comprehensive  evaluations  to  gain  insights  into  the  current  systems,  and  suggest  enhancements  through  revising  the  key  system  premises  that  contribute  to  the  vulnerabilities.  Such  revisions  facilitate  the  mitigation  of  vulnerabilities  and  allow  the  incorporation  of  new  system  pieces,  e.g.,  advanced  cryptographic  tools.  The  resulting  system  should  also  provide  satisfactory  performance  and  be  feasible  to  be  deployed  today.In  this  thesis,  I  begin  by  examining  one  general  concept  for  securing  any  network  system  -  the  virtual  private  network  (VPN).  Specifically,  I  concentrate  on  decentralized  VPN  (DVPN),  a  recent  system  revision  proposal  that  improves  user  privacy  by  distributing  VPN  proxies  to  multiple  parties,  making  it  challenging  for  anyone  to  retrieve  information  about  users  and  connections.  Nonetheless,  my  analysis  reveals  that  DVPN  fails  to  provide  adequate  security  and  privacy  guarantees  due  to  the  reliance  on  trust  placed  in  the  proxies.Unfortunately,  relieving  such  trust  dependencies  in  a  proxy-based  system  proves  to  be  a  formidable  task.  Hence,  I  pivot  to  directly  enhancing  the  specific  Internet  services  and  applications  themselves.  My  first  target  is  the  domain  name  service  (DNS),  a  fundamental  Internet  service  behind  almost  any  wild-area  network  requests.  Through  careful  scrutinization  of  existing  proposals,  I  find  that  the  presence  of  recursive  resolvers  is  the  key  system  premise  that  contribute  to  the  current  DNS  privacy  vulnerabilities.  DNS  privacy  can  be  substantially  improved  by  having  the  recursive  resolvers  operate  in  blind,  i.e.,  answering  the  queries  without  knowing  their  contents.  While  this  sounds  counter-intuitive,  it  can  actually  be  realized  through  advanced  cryptography  tools  named  private  information  retrieval  (PIR).  Following  this  direction,  I  build  PDNS,  an  efficient  and  practical  DNS  system  based  on  PIR.  Thorough  evaluations  demonstrate  that  PDNS  achieves  acceptable  performance  as  of  today  and  offers  better  privacy  preservation  than  any  state-of-the-art  proposals.PDNS  cannot  safeguard  the  interconnected  and  multi-layered  Internet  alone.  Indeed,  user  privacy  exposure  at  one  component  negates  protective  measures  at  other  components.  With  this  in  mind,  I  proceed  to  investigate  another  vital  Internet  component,  the  Hypertext  Transfer  Protocol  (HTTP)  --  the  bedrock  of  the  Web  --  where  I  identify  an  instance  of  such  a  privacy  violation.  Specifically,  Web  providers  are  harvesting  user  information  through  HTTP  cookies.  The  root  cause  is  that  current  cookies  are  semantically  oblivious,  i.e.,  they  carry  personally  identifiable  information  (PII)  but  lack  useful  information  for  analytics.  To  solve  this  issue,  I  revise  the  system  premises  and  propose  semantic  cookies  --  cookies  discarding  any  PII.  Evaluations  show  that  semantic  cookies  not  only  patch  up  privacy  leakage  in  HTTP  requests  but  also  accelerate  cookie  analytics  by  exploiting  edge  infrastructures,  providing  incentives  for  adoption.  This  exemplifies  my  system  design  philosophy  of  achieving  balance  among  performance,  security/privacy  guarantees,  and  practicality.
■590    ▼aSchool  code:  0163.
■650  4▼aComputer  science
■650  4▼aWeb  studies
■650  4▼aInformation  technology
■653    ▼aPrivate  information  retrieval
■653    ▼aWeb  components
■653    ▼aVirtual  private  network
■653    ▼aPersonally  identifiable  information
■690    ▼a0984
■690    ▼a0489
■690    ▼a0646
■71020▼aNorthwestern  University▼bComputer  Science.
■7730  ▼tDissertations  Abstracts  International▼g85-11A.
■790    ▼a0163
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17161409▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF10091 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.