Locally Operated Cooperative Key Sharing (LOCKS)
Michael Bierma, Aaron Brown, Troy DeLano, Thomas M Kroeger, Howard Poston · 2017 International Conference on Computing, Networking and Communications (ICNC) · 2017
Malicious actors are increasingly using TLS to evade deep packet inspection (DPI). In response, vendors and enterprises have turned to man-in-the-middle (MITM) proxies to enable security monitoring of encrypted traffic. This approach not only breaks the end-to-end authentication component of TLS but requires clients to trust a root certificate that allows the proxy to masquerade as any domain. This paper presents Locally Operated Cooperative Key Sharing (LOCKS), a novel system that enables local clients to share their TLS session keys with the enterprise security monitoring system, facilitating DPI without subverting authentication. We tested the performance and impact of our new approach to enterprise communications security. Specifically, we conducted tests on browser latency, user experience, and packet loss at the network security monitors. Latency change was statistically indistinguishable from normal network variation. While the workload of decrypting TLS added overhead to our security monitors, the impact was within manageable limits. Additionally, we deployed LOCKS in a real-world environment and performed initial alpha testing. A user study demonstrated no negative impact on usability.