Design and Implementation of TLS Traffic Packet Filtering Technology Based on Netfilter Framework
Cheng Jin, Chen Li · 2022
When using firewall technology to block network traffic, unexpected blocking often occurs. The main reason is that one IP will correspond to multiple domain names with the widespread use of virtual hosts. Considering this issue, this paper proposes traffic blocking technology based on SNI information. First, a Linux kernel module is developed based on the Netfilter/Iptables framework. Second, the unencrypted Server Name Indication (SNI) information in the TLS protocol is used in HTTPS communication to block traffic for domain names. Finally, specific iptables rules are configured to write into the Linux kernel and this rule supports batch writes of domain name sets. Experimental results show that this method can configure iptables traffic blocking rules for domain names and domain name sets.