implement network egress controls

Designs, builds, and validates mechanisms that control, filter, and monitor outbound network traffic from hosts, subnets, or applications. This work includes implementing and testing egress firewall/proxy rules, routing/NAT and segmentation policies, allowlists/blocklists, TLS inspection or forwarding, logging and alerting, and integrations (e.g., with DLP or SIEM) to enforce policy and demonstrate compliance.

implementnetworkegresscontrols

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.15
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$202K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the vulnerability of data-driven security policies in software-defined networks (SDNs) to overreacting to anomalous traffic, which can lead to misclassification and degrade the performance of machine learning–based intrusion detection systems. To mitigate this issue, the authors propose Safeguard, a novel mechanism that introduces a set of allow rules derived from known benign traffic. These rules operate in conjunction with data-driven policies, enabling coordinated enforcement at the network edge to prevent unintended responses while simultaneously applying firewall rules against confirmed malicious traffic. By integrating this dual-layer approach, Safeguard effectively alleviates overblocking, significantly enhancing the robustness and accuracy of SDN security policies. Experimental evaluation through a prototype implementation demonstrates the efficacy of the proposed mechanism in dynamic SDN environments.

Data-driven PolicyIntrusion DetectionNetwork Security

This work proposes an end-to-end, reproducible supervised traffic flow classification framework that addresses the limitations of traditional port- or payload-based methods in the face of encrypted and increasingly diverse network traffic. The framework integrates practical considerations from real-world measurements, incorporating flow-based feature extraction, time-aware data splitting, leakage-proof experimental design, and interpretability analysis to mitigate common methodological pitfalls. Accompanied by an open-source Jupyter Notebook implementation, it provides a complete pipeline—from traffic capture and dataset construction to model training, evaluation, and deployment. Empirical validation on real-world encrypted traffic demonstrates the approach’s effectiveness, robustness, and practical deployability.

encrypted trafficflow-based classificationmachine learning

The Door to Policy Portability might be an IP Overlay

Oct 05, 2025
BF
Behrooz Farkiani
🏛️ Washington University in St. Louis

Lack of portable Layer-3 (L3) network policy enforcement mechanisms across heterogeneous infrastructures hinders data-plane traffic security and cross-environment policy consistency. Method: We propose a novel paradigm that deeply integrates L3 network policies into the service mesh data plane, building an IP-overlay network atop Kubernetes/Istio. Policy enforcement points (PEPs) perform routing and key-based authorization for access control, while service mesh proxies uniformly enforce policies—eliminating dependence on underlying network capabilities. Contribution: This work presents the first infrastructure-agnostic, portable L3 policy enforcement mechanism. It enables unified L3–L7 policy specification and end-to-end governance. Our prototype introduces less than 1 ms latency overhead while matching the expressiveness of Kubernetes native NetworkPolicy. Experimental evaluation validates consistent, cross-cloud and hybrid-environment policy enforcement feasibility.

Building overlay layer 3 network with minimal latency for complex policiesEnabling consistent layer 3 to layer 7 policy enforcement across infrastructuresIntegrating network policy enforcement with service meshes for portable traffic protection

The Spectre of Surveillance and Censorship in Future Internet Architectures

Jan 29, 2024
MW
Michael Wrana
🏛️ University of Waterloo

Future Internet Architectures (FIAs) risk exacerbating state surveillance and network censorship while pursuing performance gains. Method: This study systematically evaluates the censorship-resistance capabilities of mainstream FIAs across packet structure, named-based addressing, and routing protocols. It introduces an ontology-driven architectural analysis to uncover intrinsic couplings between FIAs and censorship/surveillance mechanisms, develops privacy-by-design principles for censorship resistance, and proposes a multi-dimensional evaluation framework. Through architectural security analysis, protocol reverse modeling, and mapping to real-world censorship techniques, the work identifies pervasive “surveillance amplification” vulnerabilities across multiple FIAs. Contribution/Results: The study delivers an actionable privacy-enhancement technology roadmap and standardized assessment guidelines. Its findings have been cited and incorporated into ongoing discussions within IETF and IRTF working groups focused on internet architecture and trust.

Future Internet ArchitecturesGovernment SurveillanceUser Privacy Protection

Hermes: A General-Purpose Proxy-Enabled Networking Architecture

Nov 20, 2024
BF
Behrooz Farkiani
🏛️ Washington University in St. Louis

To address four key challenges—end-to-end traffic management, backward compatibility, data-plane security and privacy, and adaptability of the communication layer—this paper proposes Hermes, a proxy-centric architecture that pioneers a network-function offloading paradigm. Hermes decouples network functionalities from applications and unifies their management within reconfigurable proxies, leveraging a proxy overlay layer, HTTP tunneling/proxying, protocol translators, and a policy-based routing engine. It enables cross-subnet L3 policy routing, seamless protocol evolution, and lightweight deployment of novel architectures (e.g., Named Data Networking). Evaluation shows sub-2-ms per-hop proxy overhead; under 1,000 concurrent connections, Hermes significantly reduces end-to-end latency and amortizes connection establishment costs. Results validate improved reliability, consistent policy enforcement, and robust support for heterogeneous network architectures.

Addressing end-to-end traffic management challengesEnhancing backward compatibility and data securityImproving service delivery over the Internet

Latest Papers

What's happening recently
View more

This work addresses the challenge of efficiently and accurately translating high-level security intents into deployable device-level policies in complex heterogeneous networks, where topological reachability and device capabilities often lead to misconfigurations and delayed responses. To overcome these limitations, the authors propose an end-to-end automated framework that uniquely integrates network topology, device capabilities, and real-time cyber threat intelligence (CTI). By leveraging formal modeling, policy compilation, and constraint solving, the approach automatically refines abstract security intents into concrete, network-compliant filtering rules. Experimental validation in real-world environments demonstrates the system’s ability to correctly generate both packet-filtering and web-filtering policies, confirming its practicality, correctness, and dynamic adaptability to emerging threats.

cyber threatsmisconfigurationsnetwork constraints

This work addresses the lack of runtime network-level verification mechanisms in existing application-layer protocols, which traditionally require intrusive modifications to application code. It proposes, for the first time, shifting session-type-driven protocol monitoring into the programmable data plane by leveraging the P4 language to automatically generate packet-level monitors. This approach enforces protocol specifications directly within the network without any changes to applications. By integrating session type theory with network verification algorithms, the method effectively handles real-world network conditions such as packet loss and reordering. The feasibility and practicality of this network-level enforcement are demonstrated through evaluations in microservice and network function scenarios, showing its capability to efficiently enforce complex protocols at scale.

data planenetwork enforcementprotocol monitoring

为解决应用层DDoS攻击防御成本高和延迟问题,本文提出Shimmer,一种通过JIT编译规则集并进行高级优化以减少不必要工作的高效WAF。

application-layer DDoSrequest latencyweb application firewalls

Outdated or non-standard TLS configurations hinder clients’ ability to manage security risks in outbound connections. This work proposes TLSGatekeeper, a network-side system that monitors TLS handshakes in real time without requiring client modifications, dynamically identifying and blocking non-compliant connections according to organizational policies while preserving end-to-end privacy. By integrating real-time traffic analysis, policy-driven compliance validation, and high-performance packet processing, TLSGatekeeper achieves throughput up to 100 Gbps and introduces only 671 ns and 795 ns of average latency for TLS 1.3 and 1.2 handshakes, respectively. The system effectively overcomes the limitations of traditional firewalls in enforcing TLS compliance policies.

handshake analysismisconfigurationsoutbound connections

This work addresses the vulnerability of fully encrypted protocols (FEPs) to passive traffic analysis and active probing attacks, which undermines their ability to evade censorship. To mitigate this, the paper proposes Shaperd—the first lightweight, real-time traffic shaper designed specifically for FEPs. Shaperd operates at the packet level with minimal overhead and introduces a constraint-based system that enables users to generate customizable traffic patterns matching arbitrary target profiles. By doing so, it significantly enhances resistance to detection while maintaining high deployability and low observability. Experimental evaluation demonstrates that Shaperd achieves strong anti-detection capabilities with only negligible throughput overhead, offering a practical solution for privacy-preserving communication under adversarial network surveillance.

active probingcensorship circumventiondetection resilience