PRI: Privacy Preserving Inspection of Encrypted Network Traffic

被引:7
|
作者
Schiff, Liron [1 ]
Schmid, Stefan [2 ]
机构
[1] Tel Aviv Univ, Tel Aviv, Israel
[2] Aalborg Univ, Aalborg, Denmark
关键词
D O I
10.1109/SPW.2016.34
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Traffic inspection is a fundamental building block of many security solutions today. For example, to prevent the leakage or exfiltration of confidential insider information, as well as to block malicious traffic from entering the network, most enterprises today operate intrusion detection and prevention systems that inspect traffic. However, the state-of-theart inspection systems do not reflect well the interests of the different involved autonomous roles. For example, employees in an enterprise, or a company outsourcing its network management to a specialized third party, may require that their traffic remains confidential, even from the system administrator. Moreover, the rules used by the intrusion detection system, or more generally the configuration of an online or offline anomaly detection engine, may be provided by a third party, e.g., a security research firm, and can hence constitute a critical business asset which should be kept confidential. Today, it is often believed that accounting for these additional requirements is impossible, as they contradict efficiency and effectiveness. We in this paper explore a novel approach, called Privacy Preserving Inspection (PRI), which provides a solution to this problem, by preserving privacy of traffic inspection and confidentiality of inspection rules and configurations, and e.g., also supports the flexible installation of additional Data Leak Prevention (DLP) rules specific to the company.
引用
收藏
页码:296 / 303
页数:8
相关论文
共 50 条
  • [1] Privacy-Preserving Encrypted Traffic Inspection With Symmetric Cryptographic Techniques in IoT
    Chen, Dajiang
    Wang, Hao
    Zhang, Ning
    Nie, Xuyun
    Dai, Hong-Ning
    Zhang, Kuan
    Choo, Kim-Kwang Raymond
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (18) : 17265 - 17279
  • [2] PrivDPI: Privacy-Preserving Encrypted Traffic Inspection with Reusable Obfuscated Rules
    Ning, Jianting
    Poh, Geong Sen
    Loh, Jia-Ch'ng
    Chia, Jason
    Chang, Ee-Chien
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 1657 - 1670
  • [3] Privacy-Preserving Traceable Encrypted Traffic Inspection in Blockchain-Based Industrial IoT
    Zhang, Kai
    Deng, Minjun
    Gong, Bei
    Miao, Yinbin
    Ning, Jianting
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (02) : 3484 - 3496
  • [4] mmTLS: Scaling the Performance of Encrypted Network Traffic Inspection
    Yoon, Junghan
    Do, Seunghyun
    Kim, Duckwoo
    Chung, Taejoong
    Park, KyougSoo
    [J]. PROCEEDINGS OF THE 2024 USENIX ANNUAL TECHNICAL CONFERENCE, ATC 2024, 2024, : 631 - 647
  • [5] A novel privacy preserving user identification approach for network traffic
    Clarke, N.
    Li, F.
    Furnell, S.
    [J]. COMPUTERS & SECURITY, 2017, 70 : 335 - 350
  • [6] Privacy-Preserving Dynamic Learning of Tor Network Traffic
    Jansen, Rob
    Traudt, Matthew
    Hopper, Nicholas
    [J]. PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 1944 - 1961
  • [7] Privacy-preserving queries on encrypted data
    Yang, Zhiqiang
    Zhong, Sheng
    Wright, Rebecca N.
    [J]. Computer Security - ESORICS 2006, Proceedings, 2006, 4189 : 479 - 495
  • [8] Privacy Preserving Face Recognition in Encrypted Domain
    Ergun, Ovgu Ozturk
    [J]. 2014 IEEE ASIA PACIFIC CONFERENCE ON CIRCUITS AND SYSTEMS (APCCAS), 2014, : 643 - 646
  • [9] Encrypted DNS ⇒ Privacy? A Traffic Analysis Perspective
    Siby, Sandra
    Juarez, Marc
    Diaz, Claudia
    Vallina-Rodriguez, Narseo
    Troncoso, Carmela
    [J]. 27TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2020), 2020,
  • [10] Characterizing Privacy Leakage in Encrypted DNS Traffic
    Hu, Guannan
    Fukuda, Kensuke
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2023, E106B (02) : 156 - 165