BlindBox: Deep Packet Inspection Over Encrypted Traffic
Justine Sherry, Chang Lan, Raluca Ada Popa, Sylvia Ratnasamy UC Berkeley
(Work under submission).
BlindBox: Deep Packet Inspection Over Encrypted Traffic Justine - - PowerPoint PPT Presentation
BlindBox: Deep Packet Inspection Over Encrypted Traffic Justine Sherry, Chang Lan, Raluca Ada Popa, Sylvia Ratnasamy UC Berkeley (Work under submission). Intrusion Prevention Deep Packet Inspection Parental Filtering (DPI) In-network
(Work under submission).
CONNECTIONS
Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
BLACKLIST
WAREZ HACKS %
CONNECTIONS
BLACKLIST
WAREZ HACKS %
CONNECTIONS
To: Bob From:Alice Hello! Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
CONNECTIONS
To: Alice From:Bob Hello! Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
CONNECTIONS
To: Bob From:Alice Want some WAREZ? Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
CONNECTIONS
Alice:Bob DENY
BLACKLIST
WAREZ ATTACK MAD HATTER
CONNECTIONS
Alice:Bob ALLOW To: Bob From:Alice 0xce869fa98e0g…
regular expressions
packet requires over 1 day of computation on our servers!*
*J. Katz, A. Sahai, B. Waters. “Predicate Encryption Supporting Disjunctions, Polynomial Equations, and Inner Products.” EUROCRYPT 2008.
each other, ie, that their traffic be scanned by the middlebox.
BLACKLIST
WAREZ HACKS %
CONNECTIONS
Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
CONNECTIONS
Alice:Bob ALLOW
BLACKLIST
WAREZ HACKS %
CONNECTIONS
Alice:Bob ALLOW
CONNECTIONS
Alice:Bob ALLOW
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice Would you like some CAKE?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice Would you like some CAKE?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice Would you like some CAKE?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice Would you like some CAKE?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice 0xea453840eaabb90 ccdd9032….
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob ALLOW
To: Bob From:Alice Would you like some WAREZ?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
CONNECTIONS
Alice:Bob DENY
To: Bob From:Alice Would you like some WAREZ?
BLACKLIST
WAREZ: 0xeaf345…
HACKS: 0x43aa…
%: 0x678ea3…
*V. Paxson. “Bro: A System for Detecting Network Intruders in Real Time.” Computer Networks 1999.
Enterprise Cloud Provider External Site (Internet) APLOMB 1 Unencrypted Tunneled 6 2 3 5 4
Fine for NFV & APLOMB where connections are persistent.
0.2 0.4 0.6 0.8 1 5 10 15 20 CDF Tokenization Overhead Ratio Delim Tokenization : Plaintext Window Tokenization : Plaintext Delim Tokenization : gzip Window Tokenization : gzip