13 citations · 13 across the 2 of their papers we have counts for
4 papers
Accurate TLS Fingerprinting using Destination Context and Knowledge Bases
Blake Anderson, David McGrew
Network fingerprinting is used to identify applications, provide insight into network traffic, and detect malicious activity. With the broad adoption of TLS, traditional fingerprin…
Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption
Blake Anderson, Andrew Chi, Scott Dunlop +1
We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-T…
OS Fingerprinting: New Techniques and a Study of Information Gain and Obfuscation
Blake Anderson, David McGrew
Passive operating system fingerprinting reveals valuable information to the defenders of heterogeneous private networks; at the same time, attackers can use fingerprinting to recon…
Deciphering Malware's use of TLS (without Decryption)
Blake Anderson, Subharthi Paul, David McGrew
The use of TLS by malware poses new challenges to network threat detection because traditional pattern-matching techniques can no longer be applied to its messages. However, TLS al…