论文标题
HTTPS事件流相关:提高加密网络流量中的情境意识
HTTPS Event-Flow Correlation: Improving Situational Awareness in Encrypted Web Traffic
论文作者
论文摘要
在当前https占主导地位的网络流量中,实现情境意识是一个充满挑战的过程。在本文中,我们提出了一种新的方法来加密网络流量监视。首先,我们设计了一种基于其共同特征和相关时间窗口将基于主机和网络监视数据关联的方法。然后,我们分析相关性结果,以确定Web服务器的配置并监视对相关性产生负面影响的基础架构。我们描述了这些属性和可能的数据预处理技术,以最大程度地减少它们对相关性能的影响。此外,要在不同的Web服务器设置中测试相关方法的行为,并且对于最近的加密协议,我们通过将相关功能调整为TLS 1.3和QUIC进行修改。最后,我们评估了从校园网络收集的数据集上的相关方法。结果表明,虽然相关性需要监视自定义事件和流动功能,但即使使用为不久的将来设计的加密协议,它仍然是可行的。
Achieving situational awareness is a challenging process in current HTTPS-dominant web traffic. In this paper, we propose a new approach to encrypted web traffic monitoring. First, we design a method for correlating host-based and network monitoring data based on their common features and a correlation time-window. Then we analyze the correlation results in detail to identify configurations of web servers and monitoring infrastructure that negatively affect the correlation. We describe these properties and possible data preprocessing techniques to minimize their impact on correlation performance. Furthermore, to test the correlation method's behavior in different web server setups and for recent encryption protocols, we modify it by adapting the correlation features to TLS 1.3 and QUIC. Finally, we evaluate the correlation method on a dataset collected from a campus network. The results show that while the correlation requires monitoring of custom event and flow features, it remains feasible even when using encryption protocols designed for the near future.