{"id":"https://openalex.org/W4324009745","doi":"https://doi.org/10.1007/978-3-031-28486-1_6","title":"DissecTLS: A Scalable Active Scanner for\u00a0TLS Server Configurations, Capabilities, and\u00a0TLS Fingerprinting","display_name":"DissecTLS: A Scalable Active Scanner for\u00a0TLS Server Configurations, Capabilities, and\u00a0TLS Fingerprinting","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4324009745","doi":"https://doi.org/10.1007/978-3-031-28486-1_6"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-031-28486-1_6","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-28486-1_6","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-28486-1_6.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-28486-1_6.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5005401301","display_name":"Markus Sosnowski","orcid":"https://orcid.org/0000-0002-7322-5804"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Markus Sosnowski","raw_affiliation_strings":["Technical University of Munich, Munich, Germany"],"raw_orcid":"https://orcid.org/0000-0002-7322-5804","affiliations":[{"raw_affiliation_string":"Technical University of Munich, Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009418849","display_name":"Johannes Zirngibl","orcid":"https://orcid.org/0000-0002-2918-016X"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Johannes Zirngibl","raw_affiliation_strings":["Technical University of Munich, Munich, Germany"],"raw_orcid":"https://orcid.org/0000-0002-2918-016X","affiliations":[{"raw_affiliation_string":"Technical University of Munich, Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049611799","display_name":"Patrick Sattler","orcid":"https://orcid.org/0000-0001-9375-3113"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Patrick Sattler","raw_affiliation_strings":["Technical University of Munich, Munich, Germany"],"raw_orcid":"https://orcid.org/0000-0001-9375-3113","affiliations":[{"raw_affiliation_string":"Technical University of Munich, Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060144977","display_name":"Georg Carle","orcid":"https://orcid.org/0000-0002-2347-1839"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Georg Carle","raw_affiliation_strings":["Technical University of Munich, Munich, Germany"],"raw_orcid":"https://orcid.org/0000-0002-2347-1839","affiliations":[{"raw_affiliation_string":"Technical University of Munich, Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5005401301"],"corresponding_institution_ids":["https://openalex.org/I62916508"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":4.1619,"has_fulltext":true,"cited_by_count":8,"citation_normalized_percentile":{"value":0.94573317,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"110","last_page":"126"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9951000213623047,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.8494151830673218},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8158539533615112},{"id":"https://openalex.org/keywords/testbed","display_name":"Testbed","score":0.7078794240951538},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.6709824800491333},{"id":"https://openalex.org/keywords/scanner","display_name":"Scanner","score":0.5460006594657898},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.48334166407585144},{"id":"https://openalex.org/keywords/fingerprint","display_name":"Fingerprint (computing)","score":0.41283828020095825},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.33768606185913086},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.3361695110797882},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.3254183828830719},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.29409974813461304}],"concepts":[{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.8494151830673218},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8158539533615112},{"id":"https://openalex.org/C31395832","wikidata":"https://www.wikidata.org/wiki/Q1318674","display_name":"Testbed","level":2,"score":0.7078794240951538},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.6709824800491333},{"id":"https://openalex.org/C2779751349","wikidata":"https://www.wikidata.org/wiki/Q1474480","display_name":"Scanner","level":2,"score":0.5460006594657898},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.48334166407585144},{"id":"https://openalex.org/C2777826928","wikidata":"https://www.wikidata.org/wiki/Q3745713","display_name":"Fingerprint (computing)","level":2,"score":0.41283828020095825},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.33768606185913086},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3361695110797882},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.3254183828830719},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29409974813461304}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1007/978-3-031-28486-1_6","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-28486-1_6","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-28486-1_6.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"}],"best_oa_location":{"id":"doi:10.1007/978-3-031-28486-1_6","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-28486-1_6","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-28486-1_6.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[{"score":0.46000000834465027,"id":"https://metadata.un.org/sdg/8","display_name":"Decent work and economic growth"}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4324009745.pdf"},"referenced_works_count":19,"referenced_works":["https://openalex.org/W1930649250","https://openalex.org/W1989763988","https://openalex.org/W2044354000","https://openalex.org/W2236904012","https://openalex.org/W2266218113","https://openalex.org/W2275674373","https://openalex.org/W2292723020","https://openalex.org/W2302114600","https://openalex.org/W2611869631","https://openalex.org/W2904027722","https://openalex.org/W2915352631","https://openalex.org/W2962940036","https://openalex.org/W2962944260","https://openalex.org/W3083437617","https://openalex.org/W3137106894","https://openalex.org/W4210531213","https://openalex.org/W4283695260","https://openalex.org/W4296831835","https://openalex.org/W6942497107"],"related_works":["https://openalex.org/W2883256816","https://openalex.org/W2171408034","https://openalex.org/W3003320923","https://openalex.org/W2106140982","https://openalex.org/W2152313554","https://openalex.org/W2064303750","https://openalex.org/W4285042611","https://openalex.org/W1509300825","https://openalex.org/W3092582874","https://openalex.org/W2338718585"],"abstract_inverted_index":{"Abstract":[0],"Collecting":[1],"metadata":[2],"from":[3,158],"Transport":[4],"Layer":[5],"Security":[6],"(TLS)":[7],"servers":[8,87,193],"on":[9,151,178],"a":[10,163,174,183,209,216,233],"large":[11],"scale":[12],"allows":[13],"to":[14,85,111,119,189,203],"draw":[15],"conclusions":[16],"about":[17,92],"their":[18,93],"capabilities":[19,124],"and":[20,39,50,60,79,117,123,140,154,170,177,194,197,223],"configuration.":[21],"This":[22,129],"provides":[23],"not":[24],"only":[25,48],"insights":[26],"into":[27],"the":[28,52,57,63,121,126,134,137,152,155,159,206,225,230],"Internet":[29,115],"but":[30],"it":[31],"enables":[32],"use":[33],"cases":[34],"like":[35],"detecting":[36],"malicious":[37],"Command":[38],"Control":[40],"(C":[41],"&amp;C)":[42],"servers.":[43],"However,":[44],"active":[45,103,143,167],"scanners":[46],"can":[47,75],"observe":[49],"interpret":[51],"behavior":[53,64],"of":[54,125,136,165,212,220,235],"TLS":[55,104,127,138,168,199],"servers,":[56],"underlying":[58],"configuration":[59,122],"implementation":[61],"causing":[62],"remains":[65],"hidden.":[66],"Existing":[67],"approaches":[68,82,172],"struggle":[69],"between":[70],"resource":[71],"intensive":[72],"scans":[73],"that":[74,83,106,145],"reconstruct":[76,120],"this":[77,97],"data":[78],"light-weight":[80,109],"fingerprinting":[81,171,207],"aim":[84],"differentiate":[86],"without":[88],"making":[89],"any":[90],"assumptions":[91],"inner":[94],"working.":[95],"With":[96],"work":[98],"we":[99,228],"propose":[100],"DissecTLS,":[101],"an":[102,142],"scanner":[105],"is":[107],"both":[108],"enough":[110],"be":[112],"used":[113],"for":[114,215],"measurements":[116],"able":[118],"stack.":[128],"was":[130],"achieved":[131,208],"by":[132,232],"modeling":[133],"parameters":[135],"stack":[139],"derive":[141],"scan":[144],"dynamically":[146],"creates":[147],"scanning":[148,169],"probes":[149],"based":[150],"model":[153],"previous":[156],"responses":[157],"server.":[160],"We":[161,181],"provide":[162],"comparison":[164],"five":[166],"in":[173],"local":[175],"testbed":[176],"toplist":[179],"targets.":[180],"conducted":[182],"measurement":[184],"study":[185],"over":[186],"nine":[187],"weeks":[188],"fingerprint":[190],"C":[191],"&amp;C":[192],"analyzed":[195],"popular":[196],"deprecated":[198],"parameter":[200],"usage.":[201],"Similar":[202],"related":[204],"work,":[205],"maximum":[210],"precision":[211],"99":[213],"%":[214],"conservative":[217],"detection":[218],"threshold":[219],"100":[221],"%;":[222],"at":[224],"same":[226],"time,":[227],"improved":[229],"recall":[231],"factor":[234],"2.8.":[236]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":2}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
