Back to Search Start Over

Decrypting live SSH traffic in virtual environments.

Authors :
McLaren, Peter
Russell, Gordon
Buchanan, William J.
Tan, Zhiyuan
Source :
Digital Investigation; Jun2019, Vol. 29, p109-117, 9p
Publication Year :
2019

Abstract

Decrypting and inspecting encrypted malicious communications may assist crime detection and prevention. Access to client or server memory enables the discovery of artefacts required for decrypting secure communications. This paper develops the MemDecrypt framework to investigate the discovery of encrypted artefacts in memory and applies the methodology to decrypting the secure communications of virtual machines. For Secure Shell, used for secure remote server management, file transfer, and tunnelling inter alia, MemDecrypt experiments rapidly yield AES-encrypted details for a live secure file transfer including remote user credentials, transmitted file name and file contents. Thus, MemDecrypt discovers cryptographic artefacts and quickly decrypts live SSH malicious communications including the detection and interception of data exfiltration of confidential data. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
17422876
Volume :
29
Database :
Supplemental Index
Journal :
Digital Investigation
Publication Type :
Academic Journal
Accession number :
136768461
Full Text :
https://doi.org/10.1016/j.diin.2019.03.010