首页> 外国专利> Semi-active probing framework to gather threat intelligence for encrypted traffic and learn about devices

Semi-active probing framework to gather threat intelligence for encrypted traffic and learn about devices

机译:半主动探测框架,可收集威胁情报以获取加密流量并了解设备

摘要

In one embodiment, a device in a network observes traffic between a client and a server for an encrypted session. The device makes a determination that a server certificate should be obtained from the server. The device, based on the determination, sends a handshake probe to the server. The device extracts server certificate information from a handshake response from the server that the server sent in response to the handshake probe. The device uses the extracted server certificate information to analyze the traffic between the client and the server.
机译:在一个实施例中,网络中的设备观察客户端和服务器之间的通信以进行加密会话。设备确定应从服务器获取服务器证书。该设备基于该确定,将握手探测发送到服务器。设备从服务器响应握手探针发送的服务器的握手响应中提取服务器证书信息。设备使用提取的服务器证书信息来分析客户端和服务器之间的流量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号