Privacy-enhanced Deep Packet Inspection at Outsourced Middlebox
Hongwei Li, Hao Ren, Dongxiao Liu, Xuemin Shen
Abstract
Hongwei Li, Hao Ren, Dongxiao Liu, Xuemin Shen
Abstract
Outsourcing middlebox services to public cloud has become a prevalent choice among enterprises to reduce the facility deployment and management costs. However, the packet payload and inspection rule are inevitably exposed to the cloud server when network traffic is redirected to the middlebox. Although HTTPS protocols are able to conceal the content of packet using end-to-end encryption, it becomes challenge to perform deep packet inspection (DPI) over the encrypted traffic. In this paper, we propose a privacy-enhanced DPI (PE-DPI) scheme that is compatible with current HTTPS protocols. PE-DPI leverages a homomorphic encryption system as the building block to achieve DPI functions including keyword matching and malware detection on two non-collusion cloud servers. PE-DPI allows all the connections to share the same encrypted inspection rule, which significantly reduces the connection initialization costs. PE-DPI is able to preserve the confidentiality of packet payload and inspection rule by processing DPI over ciphertext domain. Extensive experiments demonstrate that PE-DPI out-performs the existing schemes in inspection rule preparation, sender side encryption and receiver side verification overheads.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Outsourcing middlebox services to public cloud has become a prevalent choice among enterprises to reduce the facility deployment and management costs. However, the packet payload and inspection rule are inevitably exposed to the cloud server when network traffic is redirected to the middlebox. Although HTTPS protocols are able to conceal the content of packet using end-to-end encryption, it becomes challenge to perform deep packet inspection (DPI) over the encrypted traffic. In this paper, we propose a privacy-enhanced DPI (PE-DPI) scheme that is compatible with current HTTPS protocols. PE-DPI leverages a homomorphic encryption system as the building block to achieve DPI functions including keyword matching and malware detection on two non-collusion cloud servers. PE-DPI allows all the connections to share the same encrypted inspection rule, which significantly reduces the connection initialization costs. PE-DPI is able to preserve the confidentiality of packet payload and inspection rule by processing DPI over ciphertext domain. Extensive experiments demonstrate that PE-DPI out-performs the existing schemes in inspection rule preparation, sender side encryption and receiver side verification overheads.
Key concepts: Deep packet inspection, Computer science, Computer network, Encryption, Network packet, Cloud computing, Server, Computer security