Network forensics of SSL/TLS encrypted channels

被引:0
|
作者
Wu, Meng-Da [1 ]
Wolthusen, Stephen [1 ]
机构
[1] Univ London, Royal Holloway, Informat Secur Grp, London WC1E 7HU, England
关键词
SSL/TLS; network forensics; traffic classification; sequence alignment;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Network forensics is increasingly hampered by the ubiquitous use of encrypted channels by legitimate and illegitimate network traffic. Both types of traffic are frequently tunneled over application-layer encryption mechanisms, generally using the ubiquitous TLS (SSL) protocol. This results in traditional network forensics tools being largely limited to recording external characteristics (source and origin addresses and ports, time and traffic patterns), but with little insight into content and purpose of the traffic. We propose that a precise characterization of encrypted traffic not only in the form of the external characteristics but also through the analysis of the exact mechanisms, variants and options used for the encrypted channel but visible without access to key material along with a fine-grained analysis of the traffic patterns itself incorporating domain knowledge of the SSL/TLS protocol can yield valuable insights and help to classify traffic into legitimate traffic, illegitimate immediate traffic (e.g. as caused by a Trojan). It can also characterize traffic that is added to an existing data stream by an illegitimate source. In this paper, we therefore present and characterize different traffic types and subsequently analyze this traffic, including the SSL/TLS protocol data units using selected sequence mining techniques.
引用
收藏
页码:303 / 312
页数:10
相关论文
共 50 条
  • [1] TLS/SSL Encrypted Traffic Classification with Autoencoder and Convolutional Neural Network<bold> </bold>
    Yang, Ying
    Kang, Cuicui
    Gou, Gaopeng
    Li, Zhen
    Xiong, Gang
    [J]. IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 362 - 369
  • [2] A Hybrid Method for Service Identification of SSL/TLS Encrypted Traffic
    Ding, Rusheng
    Li, Wenmin
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 250 - 253
  • [3] STNN: A Novel TLS/SSL Encrypted Traffic Classification System based on Stereo Transform Neural Network
    Zhang, Yu
    Zhao, Shiman
    Zhang, Jianzhong
    Ma, Xiaowei
    Huang, Feilong
    [J]. 2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 907 - 910
  • [4] Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks
    Meyer, Christopher
    Somorovsky, Juraj
    Weiss, Eugen
    Schwenk, Joerg
    Schinzel, Sebastian
    Tews, Erik
    [J]. PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 733 - 748
  • [5] An SFC-enabled approach for processing SSL/TLS encrypted traffic in Future Enterprise Networks
    Cunha, Vitor A.
    de Carvalho, Marcio B.
    Corujo, Daniel
    Barraca, Joao P.
    Gomes, Diogo
    Schaeffer-Filho, Alberto E.
    dos Santos, Carlos R. P.
    Granville, Lisandro Z.
    Aguiar, Rui L.
    [J]. 2018 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2018, : 1018 - 1024
  • [6] Deep Forest with LRRS Feature for Fine-grained Website Fingerprinting with Encrypted SSL/TLS
    Zhang, Ziqing
    Karig, Cuicui
    Xiong, Gang
    Li, Zhen
    [J]. PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT (CIKM '19), 2019, : 851 - 860
  • [7] A Method for Service Identification of SSL/TLS Encrypted Traffic with the Relation of Session ID and Server IP
    Kim, Sung-Min
    Goo, Young-Hoon
    Kim, Myung-Sup
    Choi, Soo-Gil
    Choi, Mi-Jung
    [J]. 2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 487 - 490
  • [8] Network Forensics for Encrypted SCADA Device Programming Traffic
    Mellish, Robert
    Graham, Scott
    Dunlap, Stephen
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 465 - 472
  • [9] CUDA-SSL: SSL/TLS Accelerated by GPU
    Lee, Wai-Kong
    Wong, Xian-Fu
    Goi, Bok-Min
    Phan, Raphael C. -W.
    [J]. 2017 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2017,
  • [10] Lesson 173: SSL and TLS
    Greenfield, David
    [J]. Network Magazine, 2002, 17 (12):