A Transport-Level Proxy for Secure Multimedia Streams

نویسندگان

  • King P. Fung
  • Rocky K. C. Chang
چکیده

service, firewalls need more than static packet filtering and application-level proxies. SOCKS is an application-independent transport-level proxy that offers user-level authentication and data encryption. An extended SOCKS UDP binding model with appropriate socket calls is proposed to provide complete support for UDP-based, multimedia streaming applications. T he increasing popularity of multimedia streaming applications, such as RealNetworks' RealPlayer and Microsoft's NetMeeting and Windows Media Player, pose challenges to the Internet infrastructure , particularly in providing secure firewall traversal for video and audio streams. Static packet filtering, the approach used by firewalls today, cannot adequately support the security needs of these applications for several reasons. First, common packet-filtering policies block almost all incoming user datagram protocol (UDP) traffic except for a few services such as the domain name service (DNS), network time protocol (NTP), and Archie. 1 Many multimedia streaming applications, however, employ UDP for data transport because for multimedia streaming, minimal delay and delay jitter is more important than total reliability. Second, the problem with UDP unicast also applies to IP multicast, which supports UDP only. IP multicast, nevertheless, is essential to a scalable solution for Internet-wide multimedia streaming. Finally, in multimedia streaming the UDP ports on the client and server sides are usually dynamically assigned through the application protocol, which is further complicated by the network address translation (NAT) performed by firewalls. As a result, special configurations, such as fixing a particular UDP port for receiving multi-media streams, are often required. 2 This article investigates the suitability of SOCKS, a transport-level proxy solution adopted by the Internet Engineering Task Force's Authenticated Firewall Traversal Working Group, for supporting multimedia streaming applications. 3 The name SOCKS came from Secure Sockets, originally developed by David Koblas and Michelle Koblas. 4 Specifically, we identify two problems encountered by SOCKS: a mismatch of call sequences between the SOCKS' transport model and multimedia streaming protocols' transport models, and inadequate socket call support for UDP binding. Failure to resolve these problems results in the firewall's blocking of the multimedia streams. We use the real-time streaming protocol (RTSP), an IETF-proposed standard, to illustrate the problems, and we propose an enhanced SOCKS to provide complete support for UDP-based applications, particularly multimedia streaming applications.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Proxy Caching for Quality Adaptive Multimedia Streams in the Internet: A Performance Perspective

Multimedia proxy caching (MCaching) presents a cost-effective solution to support large scale access to high quality multimedia streams over the Internet. However, introducing the notion of “quality” of cached streams adds a new dimension to the evaluation space and complicates the problem. This paper proposes a comprehensive framework for the evaluation of multimedia proxy caching mechanisms. ...

متن کامل

Secure Transcoding of Internet Content

In this paper, we introduce a secure transcoding framework that enables network intermediaries such as proxies to transcode multimedia data without violating end-to-end security guarantees. In our approach, an encoder decomposes a data stream at the source into multiple streams, encrypts each stream independently, and annotates each stream with clear-text metadata. An intermediary performs tran...

متن کامل

Proxy Caching Mechanism for Multimedia Playback Streams in the Internet

Despite the success of proxy caching in the Web, proxy servers have not been used effectively for caching of Internet multimedia streams such as audio and video. Explosive growth in demand for web-based streaming applications justifies the need for caching popular streams at a proxy server close to the interested clients. Because of the need for congestion control in the Internet, multimedia st...

متن کامل

Design Considerations for an RTSP - Based Pre x - Caching Proxy for Multimedia Streams

Multimedia streaming applications typically experience high start-up delay, due to large protocol overheads and the poor delay, throughput, and loss properties of the Internet. Internet service providers can improve performance by caching the initial segment (the preex) of popular streams at proxies near the requesting clients. This paper analyzes the protocol and architectural challenges of re...

متن کامل

Protocol Considerations for a Pre x-Caching Proxy for Multimedia Streams

The increasing popularity of multimedia streaming applications introduces new challenges in content distribution. Web-initiated multimedia streams typically experience high start-up delay, due to large protocol overheads and the poor delay, throughput, and loss properties of the Internet. Internet service providers can improve performance by caching the initial segment (the preex) of popular st...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IEEE Internet Computing

دوره 4  شماره 

صفحات  -

تاریخ انتشار 2000