Title
Turning Active Tls Scanning To Eleven
Abstract
Transport Layer Security (TLS) is the fundament of today's web security, but the majority of deployments are misconfigured and left vulnerable to a phletora of attacks. This negatively affects the overall healthiness of the TLS ecosystem, and as such all the protocols that build on top of it. Scanning a larger number of hosts or protocols such as the numerous IPv4-wide scans published recently for a list of known attacks in TLS is non-trivial. This is due to the design of the TLS handshake, where the server chooses the specific cipher suite to be used. Current scanning approaches have to establish an unnecessary large number of connections and amount of traffic. In this paper we present and implemented different optimized strategies for TLS cipher suite scanning that, compared to the current best practice, perform up to 3.2 times faster and with 94% less connections used while being able to do exhaustive scanning for many vulnerabilities at once. We thoroughly evaluated the algorithms using practical scans and an additional simulation for evaluating current cipher suite practices at scale. With this work full TLS cipher suite scans are brought to a new level, making them a practical tool for further empiric research.
Year
DOI
Venue
2017
10.1007/978-3-319-58469-0_1
ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017
Keywords
Field
DocType
Cipher suite scanning, SSL, TLS, Network security
Internet security,Handshake,Computer security,Computer science,Network security,Cipher suite,Transport Layer Security,Embedded system
Conference
Volume
ISSN
Citations 
502
1868-4238
1
PageRank 
References 
Authors
0.35
10
2
Name
Order
Citations
PageRank
Wilfried Mayer110.35
martin schmiedecker2163.06