Enhancing the Security of a Private Network by Using A Multi-level Hierarchical NAT Scheme

Shie Yuan Wang, Yu Hsun Yuan*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Nowadays, attacks coming from the Internet are posing serious threats to the hosts in an institution, campus, company, etc. The Network Address Translator (NAT) is a device that allows a host in a private network to interact with the hosts on the public Internet. Due to the property of NAT, unless a host that is behind a NAT actively contacts a host on the Internet, hosts on the Internet cannot actively reach the host behind the NAT. In this work, we exploit NATs and propose a multi-level hierarchical NAT scheme to protect and enhance the security of a private network. We have designed and implemented our scheme over P4 programmable hardware switches. Experimental results show that our scheme functions correctly and provides high throughput, low latency, and high stability. In addition, according to our tests, our scheme works correctly with most existing network applications.

Original languageEnglish
Title of host publication2022 IEEE 23rd International Conference on High Performance Switching and Routing, HPSR 2022
PublisherIEEE Computer Society
Pages157-162
Number of pages6
ISBN (Electronic)9781665406079
DOIs
StatePublished - 2022
Event23rd IEEE International Conference on High Performance Switching and Routing, HPSR 2022 - Taicang, Jiangsu, China
Duration: 6 Jun 20228 Jun 2022

Publication series

NameIEEE International Conference on High Performance Switching and Routing, HPSR
Volume2022-June
ISSN (Print)2325-5595
ISSN (Electronic)2325-5609

Conference

Conference23rd IEEE International Conference on High Performance Switching and Routing, HPSR 2022
Country/TerritoryChina
CityTaicang, Jiangsu
Period6/06/228/06/22

Keywords

  • NAT
  • Network security
  • P4

Fingerprint

Dive into the research topics of 'Enhancing the Security of a Private Network by Using A Multi-level Hierarchical NAT Scheme'. Together they form a unique fingerprint.

Cite this