Efficient and Transparent Method for Large-Scale TLS Traffic Analysis of Browsers and Analogous Programs

المؤلفون المشاركون

Zhuang, Yi
Pan, Jiaye
Sun, Binglin

المصدر

Security and Communication Networks

العدد

المجلد 2019، العدد 2019 (31 ديسمبر/كانون الأول 2019)، ص ص. 1-22، 22ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2019-10-27

دولة النشر

مصر

عدد الصفحات

22

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Many famous attacks take web browsers as transmission channels to make the target computer infected by malwares, such as watering hole and domain name hijacking.

In order to protect the data transmission, the SSL/TLS protocol has been widely used to defeat various hijacking attacks.

However, the existence of such encryption protection makes the security software and devices confront with the difficulty of analyzing the encrypted malicious traffic at endpoints.

In order to better solve this kind of situation, this paper proposes a new efficient and transparent method for large-scale automated TLS traffic analysis, named as hyper TLS traffic analysis (HTTA).

It extracts multiple types of valuable data from the target system in the hyper mode and then correlates them to decrypt the network packets in real time, so that overall data correlation analysis can be performed on the target.

Additionally, we propose an aided reverse engineering method to support the analysis, which can rapidly identify the target data in different versions of the program.

The proposed method can be applied to the endpoints and cloud platforms; there are no trust risk of certificates and no influence on the target programs.

Finally, the real experimental results show that the method is feasible and effective for the analysis, which leads to the lower runtime overhead compared with other methods.

It covers all the popular browser programs with good adaptability and can be applied to the large-scale analysis.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. 2019. Efficient and Transparent Method for Large-Scale TLS Traffic Analysis of Browsers and Analogous Programs. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-22.
https://search.emarefa.net/detail/BIM-1210611

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Pan, Jiaye…[et al.]. Efficient and Transparent Method for Large-Scale TLS Traffic Analysis of Browsers and Analogous Programs. Security and Communication Networks No. 2019 (2019), pp.1-22.
https://search.emarefa.net/detail/BIM-1210611

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. Efficient and Transparent Method for Large-Scale TLS Traffic Analysis of Browsers and Analogous Programs. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-22.
https://search.emarefa.net/detail/BIM-1210611

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1210611