The Transport Layer Security (TLS) protocol secures communications in many types of applications and networks, but has also faced numerous attacks due to protocol and implementation vulnerabilities. Traditional methods for identifying vulnerable TLS hosts, such as periodic scans, are inefficient in dynamic network environments. Moreover, they provide only snapshots of vulnerable hosts at discrete points in time. Alternatively, TLS monitoring tools exploit Intrusion Detection Systems and customized rules for detecting TLS vulnerabilities. We propose E-TLS-Monitor, a tool performing real-time network analysis to identify vulnerable TLS connections using various integrated tools for intrusion detection, TLS testing, certificate validation, or network scanning. Additionally, E-TLS-Monitor has knowledge about the software and hardware of the monitored target systems and exploits information retrieved from the MITRE Common Vulnerabilities and Exposures database to focus on relevant threats. E-TLS-Monitor is faster and more effective than Threat-TLS, a previously proposed monitoring tool for detecting vulnerable TLS connections in networked contexts.

An Approach for Detecting Vulnerable TLS Connections Through Network Monitoring, Intrusion Detection and TLS Testing Tools / Berbecaru, D.G., Lioy, A.. - (2026), pp. 2747-2752. (50th IEEE Annual Computers, Software, and Applications Conference, COMPSAC 2026 Madrid (ESP) 07-10 July 2026) [10.1109/compsac69091.2026.00413].

An Approach for Detecting Vulnerable TLS Connections Through Network Monitoring, Intrusion Detection and TLS Testing Tools

Berbecaru, Diana Gratiela;Lioy, Antonio
2026

Abstract

The Transport Layer Security (TLS) protocol secures communications in many types of applications and networks, but has also faced numerous attacks due to protocol and implementation vulnerabilities. Traditional methods for identifying vulnerable TLS hosts, such as periodic scans, are inefficient in dynamic network environments. Moreover, they provide only snapshots of vulnerable hosts at discrete points in time. Alternatively, TLS monitoring tools exploit Intrusion Detection Systems and customized rules for detecting TLS vulnerabilities. We propose E-TLS-Monitor, a tool performing real-time network analysis to identify vulnerable TLS connections using various integrated tools for intrusion detection, TLS testing, certificate validation, or network scanning. Additionally, E-TLS-Monitor has knowledge about the software and hardware of the monitored target systems and exploits information retrieved from the MITRE Common Vulnerabilities and Exposures database to focus on relevant threats. E-TLS-Monitor is faster and more effective than Threat-TLS, a previously proposed monitoring tool for detecting vulnerable TLS connections in networked contexts.
2026
979-8-3315-4497-3
File in questo prodotto:
File Dimensione Formato  
449701c750.pdf

accesso riservato

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 433.13 kB
Formato Adobe PDF
433.13 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3015456