Turning Active TLS Scanning to Eleven

نویسندگان

  • Wilfried Mayer
  • Martin Schmiedecker
چکیده

Transport Layer Security (TLS) is the fundament of today’s web security, but the majority of deployments are misconfigured and left vulnerable to a phletora of attacks. This negatively affects the overall healthiness of the TLS ecosystem, and as such all the protocols that build on top of it. Scanning a larger number of hosts or protocols such as the numerous IPv4-wide scans published recently for a list of known attacks in TLS is non-trivial. This is due to the design of the TLS handshake, where the server chooses the specific cipher suite to be used. Current scanning approaches have to establish an unnecessary large number of connections and amount of traffic. In this paper we present and implemented different optimized strategies for TLS cipher suite scanning that, compared to the current best practice, perform up to 3.2 times faster and with 94% less connections used while being able to do exhaustive scanning for many vulnerabilities at once. We thoroughly evaluated the algorithms using practical scans and an additional simulation for evaluating current cipher suite practices at scale. With this work full TLS cipher suite scans are brought to a new level, making them a practical tool for further empiric research.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Automatic Registration of TLS-TLS and TLS-MLS Point Clouds Using a Genetic Algorithm

Registration of point clouds is a fundamental issue in Light Detection and Ranging (LiDAR) remote sensing because point clouds scanned from multiple scan stations or by different platforms need to be transformed to a uniform coordinate reference frame. This paper proposes an efficient registration method based on genetic algorithm (GA) for automatic alignment of two terrestrial LiDAR scanning (...

متن کامل

Occlusion Area as Suitable Guidance for Terrestrial Laser Scanner Localization

Terrestrial Laser Scanner (TLS) technology, have altered quickly data acquisition for map production in surveying. In many cases, it is impossible to complete surveying of the desired area without TLS displacement in one station to another. Occlusion is innate in data acquisition, with this type of device. To solve this problem, TLS devices should be placed in different locations and scanning o...

متن کامل

Estimating Single-Tree Crown Biomass of Norway Spruce by Airborne Laser Scanning: A Comparison of Methods with and without the Use of Terrestrial Laser Scanning to Obtain the Ground Reference Data

Several methods to conduct single-tree inventories using airborne laser scanning (ALS) have been proposed, and even terrestrial laser scanning (TLS) has recently emerged as a possible tool for the collection of forest inventory data. In the present study, a novel methodological framework for a combined use of ALS and TLS in an inventory was tested and compared to a method without the use of TLS...

متن کامل

Quantifying sediment transfer between the front of an active alpine rock glacier and a torrential gully

The present contribution describes results from the quantification of transferred sediment volumes between the front of an active rock glacier and a torrential gully. The focus is set on the methodological approach which combines terrestrial laser scanning (TLS) generated digital terrain models (DTM) and geodetic field surveys. The aim is to compare high resolution DTMs from different dates in ...

متن کامل

Combining Airborne and Terrestrial Laser Scanning Technologies to Measure Forest Understorey Volume

A critical component of the forest ecosystem, the understorey supports the vast majority of wildlife habitat and total ecosystem floristic diversity. Remote sensing data have been developed to provide information at different scales for surveys of forest ecosystems, but obtaining information about the understorey remains a challenge. As rapid and efficient tools for forest structure attribute e...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017