HTTPS traffic analysis and client identification using passive SSL/TLS fingerprinting

Milan Čermák, Pavel Čeleda, Martin Husák, Tomáš Jirsík
2016-02-26

SCID:  54.1/z98e23x4
The encryption of network traffic complicates legitimate network monitoring, traffic analysis, and network forensics. In this paper, we present real-time lightweight identification of HTTPS clients based on network monitoring and SSL/TLS fingerprinting. Our experiment shows that it is possible to estimate the User-Agent of a client in HTTPS communication via the analysis of the SSL/TLS handshake. The fingerprints of SSL/TLS handshakes, including a list of supported cipher suites, differ among clients and correlate to User-Agent values from a HTTP header. We built up a dictionary of SSL/TLS cipher suite lists and HTTP User-Agents and assigned the User-Agents to the observed SSL/TLS connections to identify communicating clients. The dictionary was used to classify live HTTPS network traffic. We were able to retrieve client types from 95.4 % of HTTPS network traffic. Further, we discussed host-based and network-based methods of dictionary retrieval and estimated the quality of the data.
Publication Details
Publication Date
2016-02-26
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Milan Čermák
Pavel Čeleda
Martin Husák
Tomáš Jirsík
Explore More Research
Use the citation graph to discover related papers and expand your research horizons.
Click any node to explore
Download PDF
100%