Method and device for detecting and identifying cryptographic algorithms in a communication network

A method for identifying cryptographic algorithms in communication networks through packet capture and time signature analysis addresses the challenge of detecting quantum-vulnerable algorithms, providing a dynamic inventory and alert system.

WO2025201931A1PCT designated stage Publication Date: 2025-10-02ORANGE SA

Patent Information

Application Number
PCT/EP2025/057151
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-28
Filing Date
2025-03-17
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

The complexity and diversity of communication networks make it difficult to identify cryptographic algorithms vulnerable to quantum attacks, necessitating a method to quickly and accurately detect such algorithms without decoding data streams.

Method used

A method involving data packet capture, response time calculation, and time signature analysis is used to identify cryptographic algorithms by comparing measured time and data volumes with pre-determined signatures, employing statistical methods and learning models to compensate for operational disturbances.

Benefits of technology

Enables rapid and accurate identification of cryptographic algorithms, allowing for a dynamic inventory of vulnerable systems and triggering alerts for potential quantum attacks, without requiring decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025057151_02102025_PF_FP_ABST
    Figure EP2025057151_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for detecting a particular cryptographic algorithm used in a computer system, comprising steps of capturing data packets exchanged with a target machine in order to obtain initial measurements of time and data volume, calculating response delays by measuring the time elapsed between sending and receiving the captured data packets, determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets on the basis of the calculated response delays and the exchanged data volumes, determining a level of correspondence between the first time signature determined and at least one second time signature determined beforehand for a particular cryptographic algorithm, and transmitting an alert comprising at least one identifier of a source apparatus and / or of a destination apparatus of the network flow when the level of correspondence is greater than a threshold.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TITLE: Method and device for detecting and identifying cryptographic algorithms in a communications network.

[0002] Technical field

[0003] The invention belongs to the field of network and system security, and more specifically relates to a method for carrying out an inventory of cryptographic algorithms used in computer systems.

[0004] State of the prior art

[0005] Advances in quantum computing are now posing a concrete challenge to the security systems of communication networks. Indeed, while quantum algorithms, such as Shor's, Grover's, and Simon's algorithms, have so far made it possible to conceptually solve certain computational problems on which widely deployed security mechanisms are based, the emergence of computers adapted to implement these algorithms makes this threat very real.

[0006] Indeed, while the best classical algorithms for solving these problems generally have exponential complexity, quantum algorithms can produce an answer in polynomial time.

[0007] Although a sufficiently large and reliable quantum computer is not yet available to potential hackers, encrypted streams captured today by an attacker could be decrypted by quantum algorithms later and reveal secrets that may still have value in the future. It is therefore imperative to implement so-called post-quantum security mechanisms today, which maintain a high level of security against a quantum computer.

[0008] Cryptographic techniques vulnerable to attacks based on quantum computers are widely deployed in today's networks and infrastructures. It is therefore imperative to identify and update services that are likely to be affected today.

[0009] However, the extent of some communication networks and the diversity of the services they support make it difficult to easily establish a list of services likely to be affected. This difficulty in establishing an exhaustive map of vulnerable services deployed in a network is further exacerbated when users are offered the possibility of installing applications themselves on their workstations and when these applications are subject to frequent updates. Thus, the security mechanisms used to protect services are likely to vary over time.

[0010] Thus, comprehensively identifying services vulnerable to quantum attacks is a challenging and time-consuming task, often time-consuming and error-prone, especially in complex environments with many interconnected systems.

[0011] There is therefore a need for a method to quickly and accurately identify the cryptographic algorithms in use within digital infrastructures, in order to determine which ones are likely to be compromised by quantum attacks.

[0012] Summary of the invention

[0013] For this purpose, a method is proposed for detecting by a probe a particular cryptographic algorithm used in a computer system. The method is remarkable in that it comprises the following steps:

[0014] Capture data packets exchanged with a target machine to obtain initial measurements of time and data volume,

[0015] Calculate response times by measuring the time elapsed between sending and receiving captured data packets,

[0016] Determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets from the calculated response times and the volumes of data exchanged, Determining a level of correspondence between the first determined time signature and at least one second time signature determined beforehand for a particular cryptographic algorithm, and Transmitting an alert comprising at least one identifier of a device at the origin and / or a device receiving said network flow when the level of correspondence is greater than a threshold.

[0017] In this way, the method makes it possible to distinguish different types of cryptographic algorithms at low cost, without the need to decode data streams, and to trigger an alert when the use of a particular cryptographic algorithm is detected in a communication with a target machine. Such a cryptographic algorithm is, for example, implemented to encrypt data, to exchange a key, to carry out authentication or even to guarantee the integrity of a data packet.

[0018] The term "target machine" here refers to any equipment suitable for receiving and / or sending data over a communications network. This may be a physical machine, such as a server, a personal computer, a mobile communications terminal, etc., or a virtual machine running in a virtualized environment.

[0019] The invention exploits a relationship between a cryptographic method used to process a data block of a certain size, and the processing time required by a particular machine to process such a data block according to this method. More generally, the method identifies a particular cryptographic algorithm by exploiting technical characteristics of algorithms such as symmetric or asymmetric encryption algorithms, MAC, signature, key exchange, etc. Indeed, a particular cryptographic system has its own complexity, so that the observation of the inputs / outputs of the system by time and data volume measurements form a particular time signature of the cryptographic system.This time signature can be compared to a set of previously determined signatures for a variety of cryptographic systems and target machines to identify the system implemented on the target machine. This makes it possible to detect the implementation of algorithms that may present a particular vulnerability, for example a vulnerability to attacks perpetrated by quantum computers, and trigger an alert if necessary.

[0020] By deploying one or more probes in a communication network, it is thus possible to draw up a dynamic inventory of the cryptographic systems at work in a communication network in order to improve its security.

[0021] According to a particular embodiment, the method further comprises a step of analyzing the volume measurements to determine whether the captured packets comprise data encrypted in a block or stream mode, based on the conformity of the total size of the data to multiples of standard block sizes, the calculation time being estimated using the determined encryption mode, the time measurements and the quantity of application data exchanged.

[0022] Such an arrangement makes it possible to determine a subset of algorithms that can be used. In this way, the number of candidate algorithms is limited and detection performance is improved.

[0023] According to a particular embodiment, the method is such that it comprises a step of applying a sequential distinguisher type algorithm to identify recurring patterns which correspond to a specific cryptographic algorithm for which such patterns are previously identified.

[0024] In other words, the method comprises a step of applying a statistical method which takes into account a plurality of time measurements and data volumes and during which recurring patterns are identified which correspond to a specific cryptographic algorithm for which such patterns are previously identified.

[0025] Such recurring patterns correspond to values ​​(execution time, parameter size) that are representative of a cryptographic algorithm. One way to identify a cryptographic algorithm (and distinguish it from other cryptographic algorithms) is to use a time reference (e.g., execution time of the algorithm in question) and compare it to the measurement made at the time of analysis. However, it is possible that the measurement made at the time of analysis is noisy due to other events (operations performed in parallel, network latency, etc.). Using a sequential distinguisher allows us to take into account the fact that the measurement may be noisy. The principle consists of performing several time measurements. The comparison made is not based on a (discrete) reference value but on an interval (set of continuous values).At the time of analysis, the time measurement performed makes it possible to distinguish the algorithm executed according to whether this measurement is greater than the upper limit of the interval or less than the lower limit of the interval. If the measurement belongs to the reference interval, the result is undecidable (i.e.: too noisy).

[0026] In some embodiments, the method comprises a step of applying a Kul Iback-Leibler divergence to compare a distribution of measured times with distributions determined beforehand for a plurality of reference algorithms.

[0027] In this way, the method allows the identification of a particular cryptographic system in an operational environment, where measurements may be affected by disturbance factors such as network latency or concurrent processes on the target machine. The application of such statistical processing makes it possible to compensate for these disturbances and provide reliable results despite the unforeseen events inherent in any computer system in operation.

[0028] According to a particular embodiment, the method is such that the determination of a level of correspondence between the first and the second signature comprises the application of a learning model, previously trained from measurements of time and volume of data produced under conditions similar to those of the target machine, to determine a particular cryptographic algorithm from the measurements of time and volume of data exchanged by the target machine. It is thus proposed to train a learning algorithm such as an artificial neural network, a decision tree, or a regression algorithm from measurements carried out beforehand with processing times measured for different known cryptographic systems on reference machines whose performances are also known.The instants of reception and / or transmission of data packets (or instants corresponding to system calls for reception and / or transmission of data on the machine cycle) and the associated volumes of data (or data characteristic of this information, such as a time signature) are labeled by an identifier of the cryptographic system in use and used to train the learning model so as to allow the identification of a cryptographic system from such measurements.

[0029] According to another aspect, the invention relates to a device for detecting a particular cryptographic algorithm comprising a processor coupled with a communication interface and a memory in which instructions configured to implement the following steps are recorded:

[0030] Capture data packets exchanged with a target machine to obtain initial measurements of time and data volume,

[0031] Calculating response times by measuring the time elapsed between sending and receiving captured data packets, Determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets from the calculated response times and the volumes of data exchanged, Determining a level of correspondence between the first determined time signature and at least one second time signature determined beforehand for a particular cryptographic algorithm, and Transmitting an alert comprising at least one identifier of a device at the origin and / or of a device receiving said network flow when the level of correspondence is greater than a threshold. The invention also relates to a network probe comprising such a detection device, as well as a communication system comprising at least one target machine and such a probe.

[0032] In some implementations of the communication system, the probe is placed at the last bounce before the target machine or at a hypervisor in the case of a software-defined network (SDN).

[0033] In a particular embodiment, the different steps of the detection method are determined by computer program instructions.

[0034] Consequently, the invention also relates to a computer program comprising instructions adapted to the implementation of the steps of a detection method as described above, when the program is executed by a processor.

[0035] This program may use any programming language, and may be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0036] The invention also relates to a recording medium readable by a computer on which is recorded a computer program comprising instructions for executing the steps of a detection method as described above.

[0037] The information carrier may be any entity or device capable of storing the program. For example, the carrier may include a storage medium, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, flash memory, or a magnetic recording medium, such as a hard disk.

[0038] On the other hand, the information carrier may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The program according to the invention may in particular be downloaded from a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the detection method.

[0039] The various embodiments or features mentioned above may be added independently or in combination with each other, to the steps of the detection method.

[0040] The systems, devices, probes and programs have advantages similar to those of the detection method.

[0041] Brief description of the figures

[0042] Other characteristics and advantages will appear on reading a preferred embodiment described with reference to the appended drawings among which:

[0043] Figure 1 shows an example of a communication network,

[0044] Figure 2 is a flowchart illustrating the main steps of a detection method according to a particular embodiment,

[0045] Figure 3 shows a timeline of messages received and sent by a target machine in a communication network, and

[0046] Figure 4 is a block diagram illustrating the architecture of a device suitable for implementing a detection method according to a particular embodiment.

[0047] Detailed description

[0048] Figure 1 represents in a simplified manner a communication network RI comprising equipment E1 to E4. The network RI is for example a local area network (LAN) comprising servers and / or user workstations E1 to E4. Of course, the invention which will be described can be applied to any type of network and the example of Figure 1 is given only for illustrative purposes. For example, the network RI can comprise other equipment not shown, such as routers or gateways. The network RI can be a physical network or a virtual network without limiting the invention.

[0049] The RI network also comprises a probe S adapted to monitor and / or capture the traffic circulating on the network, and in particular the messages sent and / or received by the different devices. Although this is not shown in Figure 1 to simplify the description which follows, the RI network may comprise a plurality of probes S in order to monitor different branches of the network.

[0050] Thus, when a message is for example sent by the equipment El to the equipment E4, the probe S can detect and capture a data packet in which the message is transmitted and obtain a copy of it. The probe S can be adapted to thus capture data flows at different levels, for example on the physical layer, the data link layer, the transport layer or even at the application level.

[0051] The S-probe is, for example, a computing device such as a server comprising a processor, memory, and a network interface (e.g., an Ethernet or WiFi® interface). The device's memory includes program instructions configured to drive the network interface to capture and decode data packets.

[0052] The probe S is suitable for implementing a detection method according to a particular embodiment.

[0053] The S-probe is preferably deployed at a location close to the target machine, for example on the last router before the target machine or directly on the host, for example as a monitoring process, or at a hypervisor level in the case of a software-defined network (SDN).

[0054] The S probe is thus configured to capture application data packets exchanged with the target machine, without requiring access to the encrypted content of the packets.

[0055] In a first step 200, the probe monitors the traffic to and from the E4 device. The S probe monitors the traffic using at least one network interface, physical or virtual, allowing the probe to obtain a copy of the packets exchanged by the E4 device. The S probe captures in particular packets from encrypted communication flows. The probe identifies, for example, the encrypted flows to or from the E4 device from an address included in a header of a data packet. Symmetric algorithms are used to protect the application data. These are exchanged (in both directions of communication) in relatively large quantities. The probe uses this profusion of application data to obtain a sample of measurements.Most of the time, the same algorithm is used in both directions of a communication, so the probe can exploit measurements made on both incoming and outgoing traffic.

[0056] Figure 3 represents messages M1 to M5 received or sent by the target machine E4. Thus, the probe S records at least the arrival time t1 of a first application packet M1 and the transmission time t2 of a first packet M3 transmitted in response to the packet M1. These measurements make it possible to determine a response time t_rcv = t2 - t1.

[0057] The probe also calculates the volume of data n_rcv received by the target machine E4 in the interval [tl - 12[. Thus, with reference to Figure 3, n_rcv = tail le(M 1) + tail le(M2).

[0058] In a particular embodiment, the probe S performs measurements of arrival time t_snd and data volume n_snd of the packets sent by the target machine. More precisely, the probe S determines a response time t_snd from the transmission time t2 of a packet M3 and the reception time t3 of a response message M5, as well as the data volume n_snd sent in the interval [t2-t3[.

[0059] In a particular embodiment, the probe S analyzes the total size of the data packets exchanged during a step 201, and compares this total size with multiple values ​​of standard block sizes (for example, 64, 128, 256 bits) in order to determine a block cipher mode if the size is indeed a multiple of the standard block size, or a stream cipher mode if this is not the case. Indeed, block cipher algorithms use block sizes which are powers of 2, whereas in the case of a stream cipher mode, the size of the transmitted data can take any value. In step 202, the probe estimates a processing time (t_cmp) to process a certain quantity of data. In certain embodiments, the quantity of data for which the probe estimates a processing time may depend on the block or stream cipher mode, so that the probe determines a processing time per bit or per block.The estimated processing time (encryption, decryption or integrity check) of a data block of a particular size includes the processing time dedicated to the cryptographic algorithm used to encrypt or decrypt the data. Thus, the processing time t_cmp is a time signature of the cryptographic algorithm used, in the sense that in an identical operational context (network load, type of communication, type of machine, etc.), the use of a different cryptographic algorithm would have led to a different t_cmp estimate.

[0060] In step 203, the estimated processing time t_cmp is compared with a plurality of reference values ​​(t_refl, t_ref2, ..., t_refn) obtained in the laboratory for different known algorithms (a Igl, a Ig2, ..., algn) under conditions similar to those of the target machine. A correspondence between the estimated processing time for the target machine and a reference processing time obtained beforehand for a known algorithm makes it possible to identify the algorithm associated with the estimate t_cmp.

[0061] In the case of application data protected only in integrity, n_rcv, n_snd (including the size of the integrity tag), t_rcv, t_snd are used to determine the integrity algorithm implemented. These measures make it possible, for example, to differentiate a CMAC (Cipher-based Message Authentication Code) authentication mode, with a block cipher like AES, from an HMAC (Hash-based Message Authentication Code) function based on a hash function like SHA2. The duration of the calculation leading to the integrity tag depends on the size of the clear data to be protected. These measures also make it possible to differentiate between public key algorithms. However, in the case of public key algorithms, the quantity of exploitable data obtained during a given execution of the communication protocol is less important.It may therefore be necessary to rely on a set of data collected during several executions of the communication protocol. Indeed, when implementing a secure communication protocol, asymmetric algorithms are used only during a preliminary phase (i.e. before any application data is sent).

[0062] The comparison step makes it possible to obtain a level of correspondence between the time signature determined from the measurements made by the probe and a reference time signature, previously obtained by measurements carried out in the laboratory using a known algorithm. When the correspondence is significant, that is to say when the level of correspondence is greater than a particular threshold, the cryptographic algorithm used can be identified.

[0063] In some particular embodiments, the comparison comprises the application of a predictive model to characteristics of the traffic to and / or from the target machine. Such a predictive model is for example trained from measurements of time and volume of data produced under conditions similar to those of the target machine, to which an identifier of the cryptographic algorithm in use is associated. It is possible to envisage the use of a “random forest” type algorithm, regression models, artificial neural networks, etc. Once trained, the probe can present measurements of time and volumes of data to obtain a probability that a particular algorithm is used by the target machine.

[0064] In a particular embodiment, statistical techniques are applied during a step 204 to take into account and / or mitigate the effect of variations and disturbances linked to the operational context on the time measurements.

[0065] Indeed, the measurement of the quantity and size of the application data (n_rcv, n_snd) can be done relatively precisely. On the other hand, the time measurements associated with the application data (t_rcv, t_snd) can be disturbed by phenomena internal to the target machine (concurrent processes) or external (network latency). Therefore, statistical techniques are implemented in order to correctly determine the symmetric algorithm. The chosen statistical method(s) are applied when comparing t_cmp with each of the reference values ​​t_refl, t_ref2, ..., t_refn.

[0066] For example, the probe may use the sequential distinguisher method proposed by Junod (“On the Optimality of Linear, Differential and Sequential Distinguishers.”, Advances in Cryptology EUROCRYPT'03, Warsaw, Poland, Lectures Notes in Computer Science 2656, pp. 17-32, Springer-Verlag, 2003) to sequence measurements and identify recurring patterns that correspond to a specific algorithm and / or, in case of perturbed time measurements, apply the Kul Iback-Leibler divergence to compare the distribution of measured times with the expected distributions for each reference algorithm. The method thus uses a plurality of time measurements and data volumes to identify recurring patterns. Such patterns are previously identified from the same statistical method for different predefined cryptographic algorithms executed on a reference machine for data blocks of predefined size.

[0067] The principle of the "sequential distinguisher" is to carry out a sampling of measurements sequentially. For each measurement collected, it is evaluated whether a decision can be made (e.g.: the executed algorithm corresponds to algorithm X or does not correspond to algorithm Y). If the number of measurements is sufficient to make a decision, the collection is stopped (and a decision is made). More precisely, considering a probability of success (for the identification of the cryptographic algorithm) fixed at a given value, the goal is to minimize the number of measurements necessary to identify the algorithm. This therefore makes it possible to collect (on average) only the necessary number of measurements to identify the algorithm. This sequential procedure ultimately results in a more economical process in terms of measurements to be carried out and collected.

[0068] In step 205, based on the comparison, the probe identifies the most likely cryptographic algorithm used by the target machine and when the identified algorithm matches a particular algorithm, for example an algorithm exhibiting a vulnerability, it transmits an alert indicating that the target machine is using the algorithm in question. Such an alert makes it possible to constitute a dynamic inventory of the cryptographic techniques implemented in a computer system or a communication network.

[0069] The alert may be transmitted in a message and / or recorded in a database. Such an alert comprises at least one identifier of a source device and / or a recipient device of the message from which a particular cryptographic algorithm has been identified, for example an IP address, a UDP or TCP port, a machine name, etc. The alert may further comprise data making it possible to identify a protocol and / or a standard, or an application involved in the transmission of the message or message flow that triggered the alert.

[0070] In a particular embodiment, the triggering of the alert causes a reconfiguration of a filtering device, for example upon detection of a data flow associated with a cryptographic function deemed vulnerable, the alert can cause the isolation of the target machine and / or the machine at the origin of the data flow by configuring rules of a firewall or a routing table.

[0071] Figure 4 represents a simplified architecture of a device 400 adapted to implement the detection method according to a particular embodiment.

[0072] The device 400 comprises a data processing module comprising a storage space 401, for example a memory (MEM), a processing unit 402, equipped for example with a microprocessor (PROC), and controlled by a computer program (PGR) 403 whose instructions are configured to implement the detection method as described previously in relation to FIG. 2.

[0073] At initialization, the code instructions of the computer program 403 are for example loaded into the memory 401 before being executed by the processor of the processing unit 402. The microprocessor of the processing unit 402 implements, according to the instructions of the computer program 403, the steps of the detection method described above with reference to FIG. 2.

[0074] For this, in addition to the memory and the processor, the device 400 comprises communication means 404, for example an Ethernet network interface, adapted to capture data packets coming from and going to a particular target machine and to determine transmission and / or reception times for the data packets, as well as associated data volumes, and to calculate response times from the time elapsed between the sending and reception of captured application data packets.

[0075] The device 400 further comprises a module 405 for determining a time signature characteristic of a cryptographic algorithm implemented by the target machine from an estimate of the processing time of one or more data packets. The module 405 is for example implemented by computer program instructions configured to estimate a response time between the reception of an encrypted data packet and the transmission of a response to this packet by the target machine and to determine a time signature from the estimated response time.

[0076] The device 400 also comprises a module 406 for comparing the time signature estimated by the module 405 with time signatures previously calculated in a controlled environment for a variety of cryptographic algorithms. The module 406 is for example implemented by program instructions configured to determine a level of correspondence between the estimated time signature and the predetermined time signatures, and to compare this level to a predetermined threshold.

[0077] The device 400 also comprises an alert module 407, configured to transmit an alert when the level of correspondence estimated by the module 406 is greater than a threshold. The alert module is for example implemented by program instructions configured to identify the target machine and / or a service sending and / or receiving a message from which the characteristic time signature has been determined.

[0078] In a particular embodiment, the device 400 is included in a network node, for example in a probe, a gateway or a server, or in a hypervisor of a virtualized environment.

Claims

CLAIMS 1. A method of detecting by a probe a particular cryptographic algorithm used in a computer system, the method comprising the following steps: Capturing (200) data packets exchanged with a target machine to obtain initial measurements of time and data volume and calculating response times from the time elapsed between sending and receiving the captured data packets, Determine (202) a first time signature indicative of a cryptographic algorithm used to generate the captured packets from the calculated response times and the volumes of data exchanged, Determining (203) a level of correspondence between the first determined time signature and at least one second time signature determined beforehand for a particular cryptographic algorithm, said second signature being obtained from time and data volume measurements carried out beforehand for different known algorithms, and Transmit (205) an alert comprising at least one identifier of a device at the origin and / or of a device receiving said network flow when the level of correspondence is greater than a threshold.

2. Method according to claim 1 such that it further comprises a step of analyzing the volume measurements to determine whether the data is generated with a symmetric algorithm in a block or stream mode or with a public key algorithm, based on the conformity of the total size of the data to multiples of standard block sizes, the calculation time being estimated using the determined generation mode, the time measurements and the quantity of application data exchanged.

3. Method according to any one of the preceding claims such that it comprises a step of applying a sequential distinguisher type algorithm to identify recurring patterns that match a specific cryptographic algorithm for which such patterns are previously identified.

4. Method according to any one of the preceding claims such that it comprises a step of applying a Kullback-Leibler divergence to compare a distribution of measured times with distributions determined beforehand for a plurality of reference algorithms.

5. Method according to any one of the preceding claims in which the determination of a level of correspondence between the first and the second signature comprises the application of a learning model, previously trained from measurements of time and volume of data produced under conditions similar to those of the target machine, to determine a particular cryptographic algorithm from the measurements of time and volume of data exchanged by the target machine.

6. A device for detecting a particular cryptographic algorithm used in a computer system, the device comprising a processor coupled with a communication interface and a memory in which instructions configured to implement the following steps are recorded: Capture data packets exchanged with a target machine to obtain initial measurements of time and data volume, Calculate response times by measuring the time elapsed between sending and receiving captured data packets, Determine a first time signature indicative of a cryptographic algorithm used to generate the captured packets from the calculated response times and the volumes of data exchanged, Determining a level of correspondence between the first determined time signature and at least one second time signature determined beforehand for a particular cryptographic algorithm, said second signature being obtained from time and data volume measurements carried out beforehand for different known algorithms, and Transmit an alert including at least one identifier of a device at the origin and / or a device receiving said network flow when the correspondence level is higher than a threshold.

7. Network probe comprising a detection device according to claim 6.

8. Communication system comprising at least one target machine and a probe according to claim 7.

9. Communication system according to claim 8 wherein the probe is placed at the last bounce before the target machine or at a hypervisor in the case of a software-defined network.

10. Computer program comprising instructions configured to implement the steps of a detection method according to any one of claims 1 to 5, when executed by a processor.

11. Storage medium readable by a processor in which program instructions are recorded configured to implement the steps of a detection method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Systems and methods for evaluating encrypted data packets in a networked environment

    US20190207954A1

  • Identifying and mitigating risks of cryptographic obsolescence

    US20200244706A1

  • Cryptocurrency mining detection using network traffic

    US20210084060A1

Cited By

  • Block cipher identification method based on quantum self-organizing fuzzy neural network

    CN121396429A

  • Normalized weak password management system and method for large-scale complex service system

    CN121907605A