An Approach for Detecting Vulnerable TLS Connections Through Network Monitoring, Intrusion Detection and TLS Testing Tools
The Transport Layer Security (TLS) protocol secures communications in many types of applications and networks, but has also faced numerous attacks due to protocol and implementation vulnerabilities. Traditional methods for identifying vulnerable TLS hosts, such as periodic scans, are inefficient in dynamic network environments. Moreover, they provide only snapshots of vulnerable hosts at discrete points in time. Alternatively, TLS monitoring tools exploit Intrusion Detection Systems and customized rules for detecting TLS vulnerabilities. We propose E-TLS-Monitor, a tool performing real-time network analysis to identify vulnerable TLS connections using various integrated tools for intrusion detection, TLS testing, certificate validation, or network scanning. Additionally, E-TLS-Monitor has knowledge about the software and hardware of the monitored target systems and exploits information retrieved from the MITRE Common Vulnerabilities and Exposures database to focus on relevant threats. E-TLS-Monitor is faster and more effective than Threat-TLS, a previously proposed monitoring tool for detecting vulnerable TLS connections in networked contexts.