BlindBox: Deep Packet Inspection over Encrypted Traffic.
Justine Sherry, Chang Lan, Raluca Ada Popa, Sylvia Ratnasamy
Abstract
Justine Sherry, Chang Lan, Raluca Ada Popa, Sylvia Ratnasamy
Abstract
Many network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middle-boxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides both of these properties. The approach of Blind-Box is to perform the deep-packet inspection directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes. We demon-strate that BlindBox enables applications such as IDS, ex-filtration detection and parental filtering, and supports real rulesets from both open-source and industrial DPI systems. We implemented BlindBox and showed that it is practical for settings with long-lived HTTPS connections. Moreover, its core encryption scheme is 3-6 orders of magnitude faster than existing relevant cryptographic schemes. CCS Concepts • Security and privacy→Cryptography; Security proto-cols; • Networks→Middleboxes / network appliances; Keywords
OpenAlex reports 25 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Many network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middle-boxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides both of these properties. The approach of Blind-Box is to perform the deep-packet inspection directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes. We demon-strate that BlindBox enables applications such as IDS, ex-filtration detection and parental filtering, and supports real rulesets from both open-source and industrial DPI systems. We implemented BlindBox and showed that it is practical for settings with long-lived HTTPS connections. Moreover, its core encryption scheme is 3-6 orders of magnitude faster than existing relevant cryptographic schemes. CCS Concepts • Security and privacy→Cryptography; Security proto-cols; • Networks→Middleboxes / network appliances; Keywords
Key concepts: Deep packet inspection, Encryption, Computer science, Network packet, Intrusion detection system, Protocol (science), Computer network, Set (abstract data type)