Domain Name Security Inspection at Line Rate: Tls Sni Extraction in the Data Plane Using P4 and Dpdk

Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno · 2025

A widely adopted approach to monitor HTTPS traffic leverages the Server Name Identification (SNI) extension of TLS. Generally, the hostname is transferred in plain text over the SNI field and Deep Packet Inspection (DPI) is used to parse the TLS header and extract the hostname. However, DPI is often performed on general-purpose processors and utilizes the kernel of the operating system, which results in an overhead to the network, especially under high traffic loads. To this end, this paper proposes offloading the identification of SNI hostnames to the data plane using P4 and the Data Plane Development Kit (DPDK). In the proposed system, a P4 Programmable Data Plane (PDP) switch is the first line of defense where most of the TLS traffic is processed. DPDK is the second line of defense which processes all TLS packets that require processing capabilities beyond what the P4 PDP switch provides. To support line rate pattern matching on the hostname, the DPDK application is offloaded to a SmartNIC, leveraging its Regex engine. Experiments on various recent and public datasets from different regions and platforms reveal that the P4 switch is capable of parsing 85%99 % of hostnames. Furthermore, performance analysis shows that the P4 switch and the DPDK application, respectively, inspect a hostname in around 1 microsecond ($\mu \mathrm{s}$) and$7 \mu ~\mathrm{s}$, achieving an order of magnitude improvement over solution running on general-purpose processors.

Read the paper · More papers on PaperTik