DissecTLS: A Scalable Active Scanner for TLS Server Configurations, Capabilities, and TLS Fingerprinting
نویسندگان
چکیده
Abstract Collecting metadata from Transport Layer Security (TLS) servers on a large scale allows to draw conclusions about their capabilities and configuration. This provides not only insights into the Internet but it enables use cases like detecting malicious Command Control (C &C) servers. However, active scanners can observe interpret behavior of TLS servers, underlying configuration implementation causing remains hidden. Existing approaches struggle between resource intensive scans that reconstruct this data light-weight fingerprinting aim differentiate without making any assumptions inner working. With work we propose DissecTLS, an scanner is both enough be used for measurements able stack. was achieved by modeling parameters stack derive scan dynamically creates scanning probes based model previous responses server. We provide comparison five in local testbed toplist targets. conducted measurement study over nine weeks fingerprint C &C analyzed popular deprecated parameter usage. Similar related work, maximum precision 99 % conservative detection threshold 100 %; at same time, improved recall factor 2.8.
منابع مشابه
Server Location Verification and Server Location Pinning: Augmenting TLS Authentication
We introduce the first known mechanism providing realtime server location verification. Its uses include enhancing server authentication (e.g., augmenting TLS) by enabling browsers to automatically interpret server location information. We describe the design of this new measurement-based technique, Server Location Verification (SLV), and evaluate it using PlanetLab. We explain how SLV is compa...
متن کاملAdvanced Client/Server Authentication in TLS
Many business transactions on the Internet occur between strangers, that is, between entities with no prior relationship and no common security domain. Traditional security approaches based on identity or capabilities do not solve the problem of establishing trust between strangers. New approaches to trust establishment are required that are secure, scalable, and portable. One new approach to m...
متن کاملThe Case for Prefetching and Prevalidating TLS Server Certificates
A key bottleneck in a full TLS handshake is the need to fetch and validate the server certificate before establishing a secure connection. We propose a mechanism by which a browser can prefetch and prevalidate server certificates so that by the time the user clicks on an HTTPS link, the server’s certificate is immediately ready to be used. Combining this with a recent proposal called Snap Start...
متن کاملProScript-TLS: Verifiable Models and Systematic Testing for TLS 1.3
As TLS progresses into major new revisions in TLS 1.3, implementers are once again tasked with upgrading existing TLS code. This includes dealing with concerns such as testing new cryptographic mechanisms while preserving backwards compatibility and preventing downgrade attacks. It would be attractive for implementers to be able to quickly extract a composite symbolic model from their evolving ...
متن کاملAutomatic Registration of TLS-TLS and TLS-MLS Point Clouds Using a Genetic Algorithm
Registration of point clouds is a fundamental issue in Light Detection and Ranging (LiDAR) remote sensing because point clouds scanned from multiple scan stations or by different platforms need to be transformed to a uniform coordinate reference frame. This paper proposes an efficient registration method based on genetic algorithm (GA) for automatic alignment of two terrestrial LiDAR scanning (...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Lecture Notes in Computer Science
سال: 2023
ISSN: ['1611-3349', '0302-9743']
DOI: https://doi.org/10.1007/978-3-031-28486-1_6