Achieving situational awareness is a challenging process in current HTTPS-dominant web traffic. In this paper, we propose a new approach to encrypted web traffic monitoring. First, we design a method for correlating host-based and network monitoring data based on their common features and a correlation time-window. Then we analyze the correlation results in detail to identify configurations of web servers and monitoring infrastructure that negatively affect the correlation. We describe these properties and possible data preprocessing techniques to minimize their impact on correlation performance. Furthermore, to test the correlation method's behavior in different web server setups and for recent encryption protocols, we modify it by adapting the correlation features to TLS 1.3 and QUIC. Finally, we evaluate the correlation method on a dataset collected from a campus network. The results show that while the correlation requires monitoring of custom event and flow features, it remains feasible even when using encryption protocols designed for the near future.
翻译:在目前HTTPS占主导地位的网络交通中,实现情况认识是一个具有挑战性的过程。 在本文中,我们提出了加密网络交通监测的新方法。 首先,我们根据主机和网络监测数据的共同特点和关联时间窗口,设计了将这些数据联系起来的方法。 然后,我们详细分析相关结果,以确定对相关关系有负面影响的网络服务器的配置和监测基础设施。我们描述这些属性和可能的预处理技术,以尽量减少其对相关性能的影响。此外,为了测试不同网络服务器设置和最近的加密协议中的关联方法行为,我们根据TLS 1.3和QUIC调整了相关特点。最后,我们评估了从校园网络收集的数据集的关联方法。结果显示,虽然相关关系要求对定制事件和流动特征进行监测,但即使使用为近期设计的加密协议也是可行的。