首页> 外文期刊>Computer communication review >BlindBox: Deep Packet Inspection over Encrypted Traffic
【24h】

BlindBox: Deep Packet Inspection over Encrypted Traffic

机译:BlindBox:基于加密流量的深度数据包检查

获取原文
获取原文并翻译 | 示例
           

摘要

Many network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middle-boxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides both of these properties. The approach of Blind-Box is to perform the deep-packet inspection directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes. We demonstrate that BlindBox enables applications such as IDS, ex-filtration detection and parental filtering, and supports real rulesets from both open-source and industrial DPI systems. We implemented BlindBox and showed that it is practical for settings with long-lived HTTPS connections. Moreover, its core encryption scheme is 3-6 orders of magnitude faster than existing relevant cryptographic schemes.
机译:许多网络中间盒执行深度数据包检查(DPI),这是一组检查数据包有效负载的有用任务。这些任务包括入侵检测(IDS),渗透检测和父母过滤。但是,长期存在的问题是,一旦通过HTTPS发送了数据包,由于有效负载已加密,中间盒将无法再完成其任务。因此,人们只能选择以下两种理想特性之一:中间盒的功能和加密的私密性。我们提出BlindBox,这是第一个同时提供这两个属性的系统。 Blind-Box的方法是直接对加密流量执行深度数据包检查。 BlindBox通过新协议和新加密方案来实现此方法。我们证明了BlindBox可以启用IDS,过滤外检测和父母过滤等应用程序,并支持来自开源DPI系统和工业DPI系统的真实规则集。我们实现了BlindBox,并显示了它对于具有长期HTTPS连接的设置的实用性。此外,其核心加密方案比现有的相关加密方案快3-6个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号