BlindBox: Deep Packet Inspection over Encrypted Traffic

被引:158
|
作者
Sherry, Justine [1 ]
Lan, Chang [1 ]
Popa, Raluca Ada [1 ,2 ]
Ratnasamy, Sylvia [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA USA
[2] Swiss Fed Inst Technol, Zurich, Switzerland
基金
美国国家科学基金会;
关键词
middlebox privacy; network privacy; searchable encryption;
D O I
10.1145/2829988.2787502
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middle boxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides both of these properties. The approach of Blind Box is to perform the deep-packet inspection directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes. We demonstrate that BlindBox enables applications such as IDS, ex filtration detection and parental filtering, and supports real rulesets from both open-source and industrial DPI systems. We implemented BlindBox and showed that it is practical for settings with long-lived HTTPS connections. Moreover, its core encryption scheme is 3-6 orders of magnitude faster than existing relevant cryptographic schemes.
引用
收藏
页码:213 / 226
页数:14
相关论文
共 50 条
  • [1] BlindBox: Deep Packet Inspection over Encrypted Traffic
    Sherry, Justine
    Lan, Chang
    Popa, Raluca Ada
    Ratnasamy, Sylvia
    [J]. SIGCOMM'15: PROCEEDINGS OF THE 2015 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2015, : 213 - 226
  • [2] SlimBox: Lightweight Packet Inspection over Encrypted Traffic
    Liu, Qin
    Peng, Yu
    Jiang, Hongbo
    Wu, Jie
    Wang, Tian
    Peng, Tao
    Wang, Guojun
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 4359 - 4371
  • [3] Monitoring IoT Encrypted Traffic with Deep Packet Inspection and Statistical Analysis
    Deri, Luca
    Sartiano, Daniele
    [J]. INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST-2020), 2020, : 85 - 90
  • [4] Towards the Detection of Encrypted BitTorrent Traffic through Deep Packet Inspection
    Carvalho, David A.
    Pereira, Manuela
    Freire, Mario M.
    [J]. SECURITY TECHNOLOGY, PROCEEDINGS, 2009, 58 : 265 - 272
  • [5] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Lotfollahi, Mohammad
    Siavoshani, Mahdi Jafari
    Zade, Ramin Shirali Hossein
    Saberian, Mohammdsadegh
    [J]. SOFT COMPUTING, 2020, 24 (03) : 1999 - 2012
  • [6] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Mohammad Lotfollahi
    Mahdi Jafari Siavoshani
    Ramin Shirali Hossein Zade
    Mohammdsadegh Saberian
    [J]. Soft Computing, 2020, 24 : 1999 - 2012
  • [7] Using Deep Packet Inspection in Cyber Traffic Analysis
    Deri, Luca
    Fusco, Francesco
    [J]. PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 89 - 94
  • [8] Privacy-Preserving Deep Packet Filtering over Encrypted Traffic in Software-Defined Networks
    Lin, Yi-Hui
    Shen, Shan-Hsiang
    Yang, Ming-Hong
    Yang, De-Nian
    Chen, Wen-Tsuen
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [9] Space efficient deep packet inspection of compressed web traffic
    Afek, Yehuda
    Bremler-Barr, Anat
    Koral, Yaron
    [J]. COMPUTER COMMUNICATIONS, 2012, 35 (07) : 810 - 819
  • [10] COIN: A fast packet inspection method over compressed traffic
    Sun, Xiuwen
    Li, Hao
    Zhao, Dan
    Lu, Xingxing
    Hou, Kaiyu
    Hu, Chengchen
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 127 : 122 - 134