Using deep neural networks to hunt malicious TLS certificates
A team of researchers at Cyxtera Technologies has recently proposed a neural network-based method for identifying malicious use of web certificates. Their approach, outlined in a paper published in ACM Digital Library, uses the content of transport layer security (TLS) certificates to identify legitimate certificates, as well as malicious patterns used by attackers. Encryption is an increasingly popular way of securing communications and exchanges of data online so that they cannot be intercepted and accessed by third parties. Despite its many advantages, encryption also allows cybercriminals to hide their messages and avoid detection when carrying out malware attacks. Moreover, encryption can give online users a false sense of security, as many web browsers display a green lock symbol when the connection to a website is encrypted, even when these websites are actually executing phishing attacks.
Nov-5-2018, 18:18:12 GMT