Processing math: 100%
Selective HTTPS traffic manipulation at middleboxes for BYOD devices | IEEE Conference Publication | IEEE Xplore

Selective HTTPS traffic manipulation at middleboxes for BYOD devices


Abstract:

HTTPS has become a vital component of the WWW ecosystem. However, today's application-layer middleboxes in the cloud are largely “blind” to HTTPS traffic. We propose a no...Show More

Abstract:

HTTPS has become a vital component of the WWW ecosystem. However, today's application-layer middleboxes in the cloud are largely “blind” to HTTPS traffic. We propose a novel system infrastructural solution, called CloudEye, that allows middleboxes to selectively manipulate HTTPS traffic. A key design philosophy of CloudEye is to hide all the complexity from client and server applications (thus being transparent to them) and to have middlebox-related functions managed by a dedicated OS service. CloudEye provides control of what information the middlebox can access through new techniques such as HTTPS tags and shadow connections, without changing the TLS/SSL or HTTP protocol. CloudEye is secure and easy to use. We implemented its prototype on Linux/Android, and demonstrated its low overhead and rich use cases on off-the-shelf mobile devices and cloud servers.
Date of Conference: 10-13 October 2017
Date Added to IEEE Xplore: 23 November 2017
ISBN Information:
Conference Location: Toronto, ON, Canada

I. Introduction

HTTPS is the secure version of HTTP. It consists of HTTP over a TCP connection encrypted by Transport Layer Security (TLS) or Secure Sockets Layer (SSL)

We use “TLS” to refer to TLS and SSL unless otherwise noted.

. HTTPS traffic is growing at an unprecedented rate. It accounts for 40% of the overall Internet traffic [32], and a recent report estimates its growth to be 40% every six months [1]. This is partly attributed to increased concern about Internet privacy. Also, new web protocols such as HTTP/2 [21] and QUIC [11] use encryption by default or mandatorily.

Contact IEEE to Subscribe

References

References is not available for this document.