• DocumentCode
    3672879
  • Title

    Network-Based HTTPS Client Identification Using SSL/TLS Fingerprinting

  • Author

    Husák; Cermák;Tomá Jirsík;Pavel Celeda

  • Author_Institution
    Inst. of Comput. Sci., Masaryk Univ., Brno, Czech Republic
  • fYear
    2015
  • Firstpage
    389
  • Lastpage
    396
  • Abstract
    The growing share of encrypted network traffic complicates network traffic analysis and network forensics. In this paper, we present real-time lightweight identification of HTTPS clients based on network monitoring and SSL/TLS fingerprinting. Our experiment shows that it is possible to estimate the User-Agent of a client in HTTPS communication via the analysis of the SSL/TLS handshake. The fingerprints of SSL/TLS handshakes, including a list of supported cipher suites, differ among clients and correlate to User-Agent values from a HTTP header. We built up a dictionary of SSL/TLS cipher suite lists and HTTP User-Agents and assigned the User-Agents to the observed SSL/TLS connections to identify communicating clients. We discuss host-based and network-based methods of dictionary retrieval and estimate the quality of the data. The usability of the proposed method is demonstrated on two case studies of network forensics.
  • Keywords
    "Ciphers","Dictionaries","Protocols","Monitoring","Servers","Phase measurement"
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2015 10th International Conference on
  • Type

    conf

  • DOI
    10.1109/ARES.2015.35
  • Filename
    7299941