HTTPS Event-Flow Correlation: Improving Situational Awareness in Encrypted Web Traffic

06/22/2022
by   Stanislav Špaček, et al.
0

Achieving situational awareness is a challenging process in current HTTPS-dominant web traffic. In this paper, we propose a new approach to encrypted web traffic monitoring. First, we design a method for correlating host-based and network monitoring data based on their common features and a correlation time-window. Then we analyze the correlation results in detail to identify configurations of web servers and monitoring infrastructure that negatively affect the correlation. We describe these properties and possible data preprocessing techniques to minimize their impact on correlation performance. Furthermore, to test the correlation method's behavior in different web server setups and for recent encryption protocols, we modify it by adapting the correlation features to TLS 1.3 and QUIC. Finally, we evaluate the correlation method on a dataset collected from a campus network. The results show that while the correlation requires monitoring of custom event and flow features, it remains feasible even when using encryption protocols designed for the near future.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/01/2023

DNS Privacy with Speed? Evaluating DNS over QUIC and its Impact on Web Performance

Over the last decade, Web traffic has significantly shifted towards HTTP...
research
12/14/2020

Differentiation of Sliding Rescaled Ranges: New Approach to Encrypted and VPN Traffic Detection

We propose a new approach to traffic preprocessing called Differentiatio...
research
06/24/2019

Encrypted DNS --> Privacy? A Traffic Analysis Perspective

Virtually every connection to an Internet service is preceded by a DNS l...
research
01/12/2021

Masking Host Identity on Internet: Encrypted TLS/SSL Handshake

Network middle-boxes often classify the traffic flows on the Internet to...
research
12/19/2017

Sonification of Network Traffic Flow for Monitoring and Situational Awareness

Maintaining situational awareness of what is happening within a network ...
research
08/19/2020

Early Identification of Services in HTTPS Traffic

Traffic monitoring is essential for network management tasks that ensure...
research
12/15/2017

Realistic Traffic Generation for Web Robots

Critical to evaluating the capacity, scalability, and availability of we...

Please sign up or login with your details

Forgot password? Click here to reset