Cyber-Situational Awareness in the Presence of Encryption

被引:0
|
作者
Ceesay, Ebrima N. [1 ]
Do, Thach N. [1 ]
Watters, Paul A. [2 ]
机构
[1] Leidos Inc, Reston, VA 20190 USA
[2] La Trobe Univ, Dept Comp Sci, Melbourne, Vic, Australia
关键词
cryptography; network security; threat intelligence;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Maintaining cyber-situational awareness is a critical requirement for effective threat intelligence. However, the ubiquitous presence of encryption across numerous protocols makes it ever more challenging for organizations to monitor traffic for security purposes. This paper presents the results of analyzing encrypted traffic and its metadata to provide intelligence on the communication channel. In this study, we aim to 1) analyze and decipher the protocols of TLS and IPSec concentrating on how the session key is negotiated, and 2) analyze the ciphertext of symmetric algorithms, looking for patterns or non-randomness, which by specification, should be non-observable. We demonstrate that we are able to probabilistically identify participating parties in communication, identify signature of Suite-B algorithms (AES-GCM-256), recognize cipher text in near real-time, identify encrypted data in open channel, uncover flaws in cipher modes, and identify unknown and proprietary ciphers.
引用
收藏
页码:1621 / 1626
页数:6
相关论文
共 50 条
  • [1] Development of a Cyber-Situational Awareness Model of Risk Maturity Using Fuzzy FMEA
    Chandra, Nungky Awang
    Ratna, Anak Agung Putri
    Ramli, Kalamullah
    [J]. 2020 5TH INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS 2020), 2020, : 131 - 140
  • [2] Representing network knowledge using provenance-aware formalisms for cyber-situational awareness
    Sikos, Leslie F.
    Stumptner, Markus
    Mayer, Wolfgang
    Howard, Catherine
    Voigt, Shaun
    Philp, Dean
    [J]. KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KES-2018), 2018, 126 : 29 - 38
  • [3] POSITIVE TRAIN CONTROL SECURITY An Intrusion-Detection System to Provide Cyber-Situational Awareness
    Kolli, Satish
    Lilly, Joshua
    Wijesekera, Duminda
    [J]. IEEE VEHICULAR TECHNOLOGY MAGAZINE, 2018, 13 (03): : 48 - 60
  • [4] Preserving microgrid sustainability through robust islanding detection scheme ensuring cyber-situational awareness
    Tajdinian, Mohsen
    Mohammadpourfard, Mostafa
    Weng, Yang
    Genc, Istemihan
    [J]. SUSTAINABLE CITIES AND SOCIETY, 2023, 96
  • [5] Ontology-based approach to real-time risk management and cyber-situational awareness
    Sanchez-Zas, Carmen
    Villagra, Victor A.
    Vega-Barbas, Mario
    Larriva-Novo, Xavier
    Ignacio Moreno, Jose
    Berrocal, Julio
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 141 : 462 - 472
  • [6] Cyber situational awareness
    Leopold, H.
    [J]. ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2015, 132 (02): : 97 - 100
  • [7] Cyber Situational Awareness
    Helmut Leopold
    [J]. e & i Elektrotechnik und Informationstechnik, 2015, 132 (2) : 97 - 100
  • [8] Automated Reasoning over Provenance-Aware Communication Network Knowledge in Support of Cyber-Situational Awareness
    Sikos, Leslie F.
    Stumptner, Markus
    Mayer, Wolfgang
    Howard, Catherine
    Voigt, Shaun
    Philp, Dean
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2018, PT II, 2018, 11062 : 132 - 143
  • [9] Cyber Security Situational Awareness
    Tianfield, Huaglory
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2016, : 782 - 787
  • [10] Cyber situational awareness and differential hardening
    Dwivedi, Anurag
    Tebben, Dan
    [J]. CYBER SENSING 2012, 2012, 8408