跳到主要导航 跳到搜索 跳到主要内容

Verifiable and Privacy-Preserving Deep Packet Inspection for Multiple Rule Service Providers

  • Zhentao Long
  • , Pengfei Wu
  • , Kai Zhang*
  • , Junqing Gong
  • , Jianting Ning
  • *此作品的通讯作者
  • Shanghai University of Electric Power
  • Singapore Management University
  • Wuhan University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Secure outsourced middleboxes provide deep packet inspection (DPI) for encrypted traffic that enables the detection of malicious activities in communications. However, existing DPI systems generally support only a single rule service provider (RSP), whose rule sets are limited to specific attack types. This constraint reduces inspection coverage and diminishes the accuracy of detecting diverse malicious traffic. In this paper, we present MRv-DPI, a new privacy-preserving DPI system that supports inspection rules from multiple RSPs, enabling targeted inspection for any type of attack pattern. Additionally, by considering that the middleboxes may only use partial subscribed RSPs’ rule sets to inspect each packet, our system also provides inspection results verification. To support multiple RSPs, MRv-DPI employs a key-homomorphic pseudo-random function, allowing matching between rules encrypted under distinct keys and packets encrypted under a shared key. For result verification, we design a temporal-hashed substring search trie based on trusted hardware, ensuring tamper-resistant verification against untrusted cloud-based middleboxes. To address efficiency challenges arising from increased rule sets across multiple RSPs, MRv-DPI segments both packets and rules, and assigns each rule a main sub-segment to facilitate fast filtering of benign packets. We evaluate MRv-DPI through comprehensive experiments using four public rule sets in a real client-to-server environment. Compared to existing DPI solutions, MRv-DPI not only enhances both security and functionality but also achieves up to 2× faster packet inspection and reduces communication overhead by 36.1% – 57.4%.

源语言英语
主期刊名Information Security and Cryptology - 21st International Conference, Inscrypt 2025, Revised Selected Papers
编辑Rongmao Chen, Robert H. Deng, Moti Yung
出版商Springer Science and Business Media Deutschland GmbH
275-295
页数21
ISBN(印刷版)9789819562022
DOI
出版状态已出版 - 2026
活动21st International Conference on Information Security and Cryptology, Inscrypt 2025 - Xi'an, 中国
期限: 19 10月 202522 10月 2025

出版系列

姓名Lecture Notes in Computer Science
16409 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议21st International Conference on Information Security and Cryptology, Inscrypt 2025
国家/地区中国
Xi'an
时期19/10/2522/10/25

指纹

探究 'Verifiable and Privacy-Preserving Deep Packet Inspection for Multiple Rule Service Providers' 的科研主题。它们共同构成独一无二的指纹。

引用此