Most web traffic is encrypted today.
Organizations therefore use proxies for deep inspection of network traffic contents.
For each connection, these perform a double TLS handshake and decrypt and re-encrypt all traffic, which is computationally expensive.
In addition, support for the newer HTTP/3 protocol is rare in existing solutions, so this traffic is often blocked or remains uninspected.
In this thesis, we propose a proxy offloading system using a programmable switch whose operation is described in the P4 language.
Based on a policy of destination IP addresses or domain names, some traffic bypasses the proxy, reducing the number of packets it needs to inspect.
The system also provides a proof of feasibility for transparent interception of traffic using the HTTP/3 protocol.
It is built entirely from open-source components and is therefore auditable both by the provider of the solution and by the organization that uses it.
We evaluated the solution in a virtualized environment and on a sample of the most visited websites.
The proxy load for HTTP/3 traffic on which the switch decides by itself drops by more than two orders of magnitude, while the sustainable request rate for bypass based on the IP address increases sixfold.
Adding the switch to the system becomes worthwhile when bypassed HTTP/3 traffic reaches seven percent of the traffic, and around a quarter for HTTP/2 traffic, in both cases for bypass based on the IP address.
On a sample of one hundred domains, between 87 and 98 percent of pages still work through HTTP/3 interception, depending on the client.
|