DocumentCode
3672879
Title
Network-Based HTTPS Client Identification Using SSL/TLS Fingerprinting
Author
Husák; Cermák;Tomá Jirsík;Pavel Celeda
Author_Institution
Inst. of Comput. Sci., Masaryk Univ., Brno, Czech Republic
fYear
2015
Firstpage
389
Lastpage
396
Abstract
The growing share of encrypted network traffic complicates network traffic analysis and network forensics. In this paper, we present real-time lightweight identification of HTTPS clients based on network monitoring and SSL/TLS fingerprinting. Our experiment shows that it is possible to estimate the User-Agent of a client in HTTPS communication via the analysis of the SSL/TLS handshake. The fingerprints of SSL/TLS handshakes, including a list of supported cipher suites, differ among clients and correlate to User-Agent values from a HTTP header. We built up a dictionary of SSL/TLS cipher suite lists and HTTP User-Agents and assigned the User-Agents to the observed SSL/TLS connections to identify communicating clients. We discuss host-based and network-based methods of dictionary retrieval and estimate the quality of the data. The usability of the proposed method is demonstrated on two case studies of network forensics.
Keywords
"Ciphers","Dictionaries","Protocols","Monitoring","Servers","Phase measurement"
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2015 10th International Conference on
Type
conf
DOI
10.1109/ARES.2015.35
Filename
7299941
Link To Document