Scaling the performance of modern TLS middleboxes with mmTLS네트워크 모니터링을 위한 고성능 TLS 미들박스

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 116
  • Download : 0
Modern security-monitoring TLS middleboxes play a critical role in fighting against the abuse by encrypted network traffic. Unfortunately, a TLS middlebox often suffers from huge computational overhead as it must translate and relay the encrypted traffic from one endpoint to the other. We observe that a simple TLS proxy drops the throughput of end-to-end TLS sessions by 69% to 78%. What is worse is that recent works on security enhancement of a TLS middlebox levy even more computational tax. In this paper, we present mmTLS, a scalable TLS middlebox architecture that significantly improves the traffic monitoring performance. mmTLS eliminates the traffic relaying cost as it operates on a single end-to-end TLS session by secure session key sharing. This approach is not only beneficial to performance but it also guarantees end-to-end TLS properties except for confidentiality. To detect illegal content modification, mmTLS supplements a TLS record with a private tag whose key is kept secret only to TLS endpoints. We find that the extra overhead for private tag generation and verification is minimal when augmented with the first tag generation. Our evaluation shows that mmTLS outperforms the nginx TLS proxy in the split-connection mode by a factor of 2.8 to 63.5, and achieves 133 Gbps of traffic relaying throughput.
Advisors
Park, Kyoungsooresearcher박경수researcher
Description
한국과학기술원 :전기및전자공학부,
Publisher
한국과학기술원
Issue Date
2023
Identifier
325007
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 전기및전자공학부, 2023.2,[iv, 34 p. :]

Keywords

Transport layer security▼aMiddlebox, Network monitoring▼aNetwork monitoring; 전송 계층 보안▼a미들박스▼a네트워크 모니터링

URI
http://hdl.handle.net/10203/309904
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=1032910&flag=dissertation
Appears in Collection
EE-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0