IEEJ Transactions on Electronics, Information and Systems
Online ISSN : 1348-8155
Print ISSN : 0385-4221
ISSN-L : 0385-4221
<Information and Communication Technology>
Per-Process Communication Control Mechanism in NTMobile
Takahiro YoshidaMinoru MatsuokaHidekazu Suzuki
Author information
JOURNAL RESTRICTED ACCESS

2021 Volume 141 Issue 12 Pages 1241-1249

Details
Abstract

Network Traversal with Mobility (NTMobile), which provides both IP mobility and connectivity in a mixed IPv4/IPv6 environment, can control whether or not encrypted UDP tunnel communication is allowed per node according to an access control list. However, in the case of NTMobile nodes where communication is allowed, not only authorized application communication but also malware communication can pass through NATs and firewalls. This paper proposes a new mechanism to control the communication per process. With the proposed mechanism, even if an NTMobile node is allowed to communicate, it can identify the relevant application process from the sending and receiving packets, and control the packet passing or dropping in accordance with the rules. As a result of implementing and verifying a prototype of the proposed method, we confirmed that the communication availability can be controlled for each process. We also evaluated the throughput performance and confirmed that the proposed method can achieve the performance without any practical problems by utilizing the cache function.

Content from these authors
© 2021 by the Institute of Electrical Engineers of Japan
Previous article Next article
feedback
Top