Skip to main navigation Skip to search Skip to main content

Towards a fast packet inspection over compressed HTTP traffic

  • Xiuwen Sun
  • , Kaiyu Hou
  • , Hao Li
  • , Chengchen Hu
  • Xi'an Jiaotong University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Scopus citations

Abstract

Matching multiple patterns is the key technology in firewall, Intrusion Detection Systems, etc. However, most of the web services nowadays tend to compress their traffic for less transferring data and better user experience, which has challenged the multi-pattern matching original working only on raw content. Naive and straightforward solutions towards this challenge either decompress the compressed data first and apply legacy multi-pattern matching methods, or have to scan redundant data during the matching., which are not fast and memory efficient. In this paper, we propose COmpression INspection (COIN) method for multi-pattern matching on compressed HTTP traffic. COIN does not decompress the data before matching and only scans once each bit of the traffic under inspection. We have collected real traffic data from Alexa.com top 500 and Alexa.cn top 20000 web sites and have performed the experiments under 1430 SNORT patterns. The evaluation results show that COIN is 10-31% faster than state-of-the-art approach.

Original languageEnglish
Title of host publication2017 IEEE/ACM 25th International Symposium on Quality of Service, IWQoS 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781509019830
DOIs
StatePublished - 5 Jul 2017
Event25th IEEE/ACM International Symposium on Quality of Service, IWQoS 2017 - Vilanova i la Geltru, Spain
Duration: 14 Jun 201716 Jun 2017

Publication series

Name2017 IEEE/ACM 25th International Symposium on Quality of Service, IWQoS 2017

Conference

Conference25th IEEE/ACM International Symposium on Quality of Service, IWQoS 2017
Country/TerritorySpain
CityVilanova i la Geltru
Period14/06/1716/06/17

Keywords

  • Compressed traffic
  • Deep packet inspection
  • Gzip/DEFLATE
  • Multi-pattern matching

Fingerprint

Dive into the research topics of 'Towards a fast packet inspection over compressed HTTP traffic'. Together they form a unique fingerprint.

Cite this