Pump Up the JARM: Studying the Evolution of Botnets using Active TLS Fingerprinting
Rattachement africain : gr. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
The growing adoption of network encryption protocols, like TLS, has altered the scene of monitoring network traffic. With the advent and rapid increase in network encryption mechanisms, typical deep packet inspection systems that monitor network packet payload contents are gradually becoming obsolete, while in the meantime, adversaries abuse the utilization of the TLS protocol to bypass them. In this paper, aiming to understand the botnet ecosystem in the wild, we contact IP addresses known to participate in malicious activities using the JARM tool for active probing.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
Où se fait cette recherche
-
Foundation for Research and Technology Hellas pays non établi dans la noticeStructure de recherche
-
Technical University of Crete pays non établi dans la noticeUniversité ou école supérieure
Foundation for Research and Technology Hellas et Technical University of Crete.
Une affiliation ne permet pas de déduire la nationalité d’un auteur.