4 ms·
seems like its only a matter of time then that malicious servers wrap their TLS libs in a one time randomizer that gives them the appearance of not matching oth
by mixologic 6y ago
seems like its only a matter of time then that malicious servers wrap their TLS libs in a one time randomizer that gives them the appearance of not matching other C&C hosts.
- easterncalculus 6y agoIt's a cat and mouse game. At the same time, though, it means that botnet operators (provided that they don't roll their own crypto) have to engage in that much more effort to keep their C2 infrastructure secret. That's a win for security teams, and it's definitely more effort on the attacker's part than it is on the defender's.