加密
深包检验
计算机科学
网络数据包
计算机网络
入侵检测系统
协议(科学)
集合(抽象数据类型)
嵌入式系统
实时计算
计算机安全
医学
病理
程序设计语言
替代医学
作者
Justine Sherry,Chang Lan,Raluca Ada Popa,Sylvia Ratnasamy
标识
DOI:10.1145/2785956.2787502
摘要
Many network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middleboxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides {\em both} of these properties. The approach of BlindBox is to perform the deep-packet inspection {\em directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes.
科研通智能强力驱动
Strongly Powered by AbleSci AI