activity
20162023
most citedAccurate TLS Fingerprinting using Destination Context and Knowledge Bases

13 citations · 13 across the 3 of their papers we have counts for

collaborators
Showing cs.CRShow all

5 papers · 1 filter

cs.CR2023

Assessing and Exploiting Domain Name Misinformation

Blake Anderson, David McGrew

Cloud providers' support for network evasion techniques that misrepresent the server's domain name is more prevalent than previously believed, which has serious implications for se…

cs.CR202013 cited

Accurate TLS Fingerprinting using Destination Context and Knowledge Bases

Blake Anderson, David McGrew

Network fingerprinting is used to identify applications, provide insight into network traffic, and detect malicious activity. With the broad adoption of TLS, traditional fingerprin…

cs.CR2018

Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption

Blake Anderson, Andrew Chi, Scott Dunlop +1

We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-T…

cs.CR2017

OS Fingerprinting: New Techniques and a Study of Information Gain and Obfuscation

Blake Anderson, David McGrew

Passive operating system fingerprinting reveals valuable information to the defenders of heterogeneous private networks; at the same time, attackers can use fingerprinting to recon…

cs.CR2016

Deciphering Malware's use of TLS (without Decryption)

Blake Anderson, Subharthi Paul, David McGrew

The use of TLS by malware poses new challenges to network threat detection because traditional pattern-matching techniques can no longer be applied to its messages. However, TLS al…