Fingerprinting the Shadows: Unmasking Malicious Servers with Machine Learning-Powered TLS Analysis
Andreas Theofanous, Eva Papadogiannaki, Alexander Shevtsov, Sotiris Ioannidis
Abstract
Over the last few years, the adoption of encryption in network traffic has been constantly increasing. The percentage of encrypted communications worldwide is estimated to exceed 90%. Although network encryption protocols mainly aim to secure and protect users' online activities and communications, they have been exploited by malicious entities that hide their presence in the network. It was estimated that in 2022, more than 85% of the malware used encrypted communication channels. In this work, we examine state-of-the-art fingerprinting techniques and extend a machine learning pipeline for effective and practical server classification. Specifically, we actively contact servers to initiate communication over the TLS protocol and through exhaustive requests, we extract communication metadata. We investigate which features favor an effective classification, following state-of-the-art approaches. Our extended pipeline can indicate whether a server is malicious or not with 91% precision and 95% recall, while it can specify the botnet family with 99% precision and 99% recall.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on2
Related papers
- Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionPriyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao WangCCS 2022 · 31 citations
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
- Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic AugmentationRenjie Xie, Jiahao Cao, Enhuan Dong, Mingwei Xu et al.USENIX Security 2023
- FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic ClassificationHongbo Xu, Chengxiang Si, Shuhao Li, Zhenyu Cheng et al.INFOCOM 2025 · 4 citations
- Wedjat: Detecting Sophisticated Evasion Attacks via Real-time Causal AnalysisLi Gao, Chuanpu Fu, Xinhao Deng, Ke Xu et al.KDD 2025 · 2 citations
