6 ms·
For the purposes of intrusion detection, even metadata about an encrypted connection can be helpful. You get the (potentially unencrypted) metadata about the co
by cosmie 6y ago
For the purposes of intrusion detection, even metadata about an encrypted connection can be helpful. You get the (potentially unencrypted) metadata about the connection at the beginning of it, but also a host of other metadata such as time of connections, amount of data transfer, volume/frequency of connections, etc. So even without knowing the contents, you can pick up on anomalous and suspicious activity on your network. You also get information such as the IP addresses of the endpoints and potentially hostname, which gets sent in cleartext during the SSL handshake so a server with virtual hosts and potentially multiple websites know which one is being requested and knows which certificate is appropriate to use.
For traffic inspection purposes, you can still monitor the contents of (most) encrypted packets, but have to have your own certificate on the end user's device. This is most common on corporate networks, where a company will either install their own certificate as part of their device management process or rely on third party apps like Bluecoat[1] to do that.
Once they've added their own certificate to your device's trust store, that can be used to decrypt and re-encrypt traffic in transit, without any overt indications to end users that it's being done (although you can sometimes detect if this is being done). There are ways to guard against this, such as certificate pinning[2], but that's up to each individual service setting up rather than something the end-user can do themselves.
In both cases, enterprise networks are generally one of the bigger users of such software. There are open source IDS's you can use on your home network, which won't require 100Gbps. But 100Gbps is easily achievable on an office network, particularly as you start to scale to multiple offices (and if you include intranet traffic, and not just processing outbound/external traffic).
[1] https://en.wikipedia.org/wiki/Blue_Coat_Systems https://en.wikipedia.org/wiki/Blue_Coat_Systems
[2] https://carvesystems.com/news/cert_pin/ https://carvesystems.com/news/cert_pin/