Encrypted Traffic Decryption Tools: Comparative Performance Analysis and Improvement Guidelines

1Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

With the exponential growth of encrypted communication over the internet, research into systems capable of analyzing large volumes of encrypted traffic is essential. This study focuses on evaluating the performance of two prominent tools, ssldump and tshark, in decrypting and inspecting encrypted network traffic, assuming an environment where decryption keys are available. The performance of ssldump and tshark was assessed using various metrics, including execution time, and the ability to handle different file sizes and session counts. The results showed that tshark exhibited faster processing speeds for smaller file sizes and a higher number of sessions, while ssldump demonstrated better performance for larger file sizes and fewer sessions. However, notable performance differences were not observed based solely on the type of cipher suite or encryption method used. To enhance performance, the study proposes the session-based split and conquer (SSC) technique for automating parallelization using a multi-process approach. SSC shows up to a 39× improvement in performance, depending on system capabilities and workload.

Cite

CITATION STYLE

APA

Jo, M., Jeong, H., Song, B., & Jo, H. (2024). Encrypted Traffic Decryption Tools: Comparative Performance Analysis and Improvement Guidelines. Electronics (Switzerland), 13(14). https://doi.org/10.3390/electronics13142876

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free