Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes

被引:4
|
作者
Lai, Shangqi [1 ]
Yuan, Xingliang [1 ]
Sun, Shi-Feng [1 ]
Liu, Joseph K. [1 ]
Steinfeld, Ron [1 ]
Sakzad, Amin [1 ]
Liu, Dongxi [2 ]
机构
[1] Monash Univ, Fac Informat Technol, Clayton, Vic 3800, Australia
[2] Data 61 CSIRO, Clayton, Vic 3169, Australia
关键词
Encrypted pattern matching; secure middleboxes; privacy preservation; PRIVACY;
D O I
10.1109/TDSC.2021.3065652
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network Function Virtualisation (NFV) advances the adoption of composable software middleboxes. Accordingly, cloud data centres become major NFV vendors for enterprise traffic processing. Due to the privacy concern of traffic redirection to the cloud, secure middlebox systems (e.g., BlindBox) draw much attention; they can process encrypted packets against encrypted rules directly. However, most of the existing systems supporting pattern matching based network functions require the enterprise gateway to tokenise packet payloads via sliding windows. Such tokenisation induces a considerable communication overhead, which can be over 100x to the packet size. To overcome this bottleneck, in this article, we propose the first bandwidth-efficient encrypted pattern matching protocol for secure middleboxes. We resort to a primitive called symmetric hidden vector encryption (SHVE), and propose a variant of it, aka SHVE+, to achieve constant and moderate communication cost. To speed up, we devise encrypted filters to reduce the number of accesses to SHVE+ during matching highly. We formalise the security of our proposed protocol and conduct comprehensive evaluations over real-world rulesets and traffic dumps. The results show that our design can inspect a packet over 20 k rules within 100 ms. Compared to prior work, it brings a saving of 94 percent in bandwidth consumption.
引用
收藏
页码:2609 / 2621
页数:13
相关论文
共 50 条
  • [1] Traffic Pattern Plot: Video Identification in Encrypted Network Traffic
    Kamal, Ali S.
    Bukhari, Syed M. A. H.
    Khan, Muhammad U. S.
    Maqsood, Tahir
    Fayyaz, Muhammad A. B.
    [J]. INTELLIGENT SUSTAINABLE SYSTEMS, WORLDS4 2022, VOL 2, 2023, 579 : 77 - 84
  • [2] Assuring String Pattern Matching in Outsourced Middleboxes
    Yuan, Xingliang
    Duan, Huayi
    Wang, Cong
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2018, 26 (03) : 1362 - 1375
  • [3] Secure Federated Learning: An Evaluation of Homomorphic Encrypted Network Traffic Prediction
    Sanon, Sogo Pierre
    Reddy, Rekha
    Lipps, Christoph
    Schotten, Hans Dieter
    [J]. 2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [4] Bringing Execution Assurances of Pattern Matching in Outsourced Middleboxes
    Yuan, Xingliang
    Duan, Huayi
    Wang, Cong
    [J]. 2016 IEEE 24TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2016,
  • [5] Practical Single-Round Secure Wildcard Pattern Matching
    Xu, Jun
    Zhao, Shengnan
    Zhao, Chuan
    Chen, Zhenxiang
    Liu, Zhe
    Fang, Liming
    [J]. ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, IFIP SEC 2023, 2024, 679 : 87 - 101
  • [6] Pattern Matching of Packet Payload for Network Traffic Classification
    Choi, Kwangjin
    Choi, Jun Kyun
    [J]. 2006 THE JOINT INTERNATIONAL CONFERENCE ON OPTICAL INTERNET (COIN) AND NEXT GENERATION NETWORK (NGNCON), 2006, : 394 - 396
  • [7] PPS: A Packets Pattern-based Video Identification in Encrypted Network Traffic
    Bukhari, Syed M. A. H.
    Afaq, Muhammad
    Song, Wang-Cheol
    [J]. 16TH IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING, UCC 2023, 2023,
  • [8] Accurate Encrypted Malicious Traffic Identification via Traffic Interaction Pattern Using Graph Convolutional Network
    Ren, Guoqiang
    Cheng, Guang
    Fu, Nan
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (03):
  • [9] Practical pattern matching
    Voth, D
    [J]. IEEE INTELLIGENT SYSTEMS, 2006, 21 (01) : 4 - 6
  • [10] Parallel Pattern Matching over Brotli Compressed Network Traffic
    Sun, Xiuwen
    Zhang, Guangzheng
    Wu, Di
    Yu, Qingying
    Cui, Jie
    Zhong, Hong
    [J]. 2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 477 - 484