Cyber-Situational Awareness in the Presence of Encryption

被引:0
|
作者
Ceesay, Ebrima N. [1 ]
Do, Thach N. [1 ]
Watters, Paul A. [2 ]
机构
[1] Leidos Inc, Reston, VA 20190 USA
[2] La Trobe Univ, Dept Comp Sci, Melbourne, Vic, Australia
关键词
cryptography; network security; threat intelligence;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Maintaining cyber-situational awareness is a critical requirement for effective threat intelligence. However, the ubiquitous presence of encryption across numerous protocols makes it ever more challenging for organizations to monitor traffic for security purposes. This paper presents the results of analyzing encrypted traffic and its metadata to provide intelligence on the communication channel. In this study, we aim to 1) analyze and decipher the protocols of TLS and IPSec concentrating on how the session key is negotiated, and 2) analyze the ciphertext of symmetric algorithms, looking for patterns or non-randomness, which by specification, should be non-observable. We demonstrate that we are able to probabilistically identify participating parties in communication, identify signature of Suite-B algorithms (AES-GCM-256), recognize cipher text in near real-time, identify encrypted data in open channel, uncover flaws in cipher modes, and identify unknown and proprietary ciphers.
引用
收藏
页码:1621 / 1626
页数:6
相关论文
共 50 条
  • [41] A Cyber Security Situational Awareness Framework to Track and Project Multistage Cyber Attacks
    Bhatt, Parth
    Yano, Edgar Toshiro
    Amorim, Joni
    Gustavsson, Per
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2014), 2014, : 356 - 360
  • [42] Cyber Senses: Modeling Network Situational Awareness after Biology
    Blakely, Benjamin
    [J]. 2021 RESILIENCE WEEK (RWS), 2021,
  • [43] Enhancing Cyber Situational Awareness for Cyber-Physical Systems through Digital Twins
    Eckhart, Matthias
    Ekelhart, Andreas
    Weippl, Edgar
    [J]. 2019 24TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2019, : 1222 - 1225
  • [44] Cyber Attacks Analysis Using Decision Tree Technique for Improving Cyber Situational Awareness
    Pournouri, Sina
    Akhgar, Babak
    Bayerl, Petra Saskia
    [J]. GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: THE SECURITY CHALLENGES OF THE CONNECTED WORLD, ICGS3 2017, 2016, 630 : 155 - 172
  • [45] A Conceptual Nationwide Cyber Situational Awareness Framework for Critical Infrastructures
    Bahsi, Hayretdin
    Maennel, Olaf Manuel
    [J]. SECURE IT SYSTEMS, NORDSEC 2015, 2015, 9417 : 3 - 10
  • [46] Designing a Cyber Attack Information System for National Situational Awareness
    Skopik, Florian
    Ma, Zhendong
    Smith, Paul
    Bleier, Thomas
    [J]. FUTURE SECURITY, 2012, 318 : 277 - 288
  • [47] Towards a Theoretical Framework for an Active Cyber Situational Awareness Model
    Al-Shamisi, Ahmed
    Louvieris, Panos
    Al-Mualla, Mohammed
    Mihajlov, Martin
    [J]. PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING, (IWSSIP 2016), 2016, : 263 - 268
  • [48] Cyber Situational Awareness Enhancement with Regular Expressions and an Evaluation Methodology
    Park, Hyun Kyoo
    Kim, Min Sik
    park, Moosung
    Lee, Kyungho
    [J]. MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 406 - 411
  • [49] Cyber attacks real time detection: towards a Cyber Situational Awareness for naval systems
    Jacq, Olivier
    Brosset, David
    Kermarrec, Yvon
    Simonin, Jacques
    [J]. 2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2019,
  • [50] Cyber Situational Awareness for CPS, 5G and IoT
    Chang, Elizabeth
    Gottwalt, Florian
    Zhang, Yu
    [J]. FRONTIERS IN ELECTRONIC TECHNOLOGIES: TRENDS AND CHALLENGES, 2017, 433 : 147 - 161