• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. TLS key material identification and extraction in memory: Current state and future challenges
 
  • Details
  • Full
Options
2024
Journal Article
Title

TLS key material identification and extraction in memory: Current state and future challenges

Abstract
Memory forensics is a crucial part of digital forensics as it can be used to extract valuable information such as running processes, network connections, and encryption keys from memory. The last is especially important when considering the widely used Transport Layer Security (TLS) protocol used to secure internet communication, thus hampering network traffic analysis. Particularly in the context of cybercrime investigations (such as malware analysis), it is therefore paramount for investigators to decrypt TLS traffic. This can provide vital insights into the methods and strategies employed by attackers. For this purpose, it is first and foremost necessary to identify and extract the corresponding TLS key material in memory. In this paper, we systematize and evaluate the current state of techniques, tools, and methodologies for identifying and extracting TLS key material in memory. We consider solutions from academia but also identify innovative and promising approaches used "in the wild" that are not considered by the academic literature. Furthermore, we identify the open research challenges and opportunities for future research in this domain. Our work provides a profound foundation for future research in this crucial area.
Author(s)
Baier, Daniel  
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Basse, Alexander
Universität Bonn
Hilgert, Jan-Niclas  
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Lambertz, Martin  
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Journal
Forensic Science International : FSI. Digital Investigation  
Conference
Annual Digital Forensics Research Conference 2024  
Open Access
DOI
10.1016/j.fsidi.2024.301766
Additional link
Full text
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Keyword(s)
  • Live forensics

  • Malware analysis

  • Memory forensics

  • Network forensics

  • TLS

  • Transport layer security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024