{"id":"https://openalex.org/W4400121414","doi":"https://doi.org/10.1145/3634737.3637654","title":"X-Ray-TLS: Transparent Decryption of TLS Sessions by Extracting Session Keys from Memory","display_name":"X-Ray-TLS: Transparent Decryption of TLS Sessions by Extracting Session Keys from Memory","publication_year":2024,"publication_date":"2024-06-28","ids":{"openalex":"https://openalex.org/W4400121414","doi":"https://doi.org/10.1145/3634737.3637654"},"language":"en","primary_location":{"id":"doi:10.1145/3634737.3637654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637654?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637654?download=true","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087943069","display_name":"Florent Moriconi","orcid":"https://orcid.org/0009-0001-8989-4391"},"institutions":[{"id":"https://openalex.org/I1902872","display_name":"EURECOM","ror":"https://ror.org/00sse7z02","country_code":"FR","type":"education","lineage":["https://openalex.org/I1902872","https://openalex.org/I205703379"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Florent Moriconi","raw_affiliation_strings":["AMADEUS, Villeneuve-Loubet, France","EURECOM, Biot, France","Eurecom [Sophia Antipolis] (Campus SophiaTech, 450 Route des Chappes, CS 50193 - 06904 Biot Sophia Antipolis cedex - France)"],"affiliations":[{"raw_affiliation_string":"AMADEUS, Villeneuve-Loubet, France","institution_ids":[]},{"raw_affiliation_string":"EURECOM, Biot, France","institution_ids":["https://openalex.org/I1902872"]},{"raw_affiliation_string":"Eurecom [Sophia Antipolis] (Campus SophiaTech, 450 Route des Chappes, CS 50193 - 06904 Biot Sophia Antipolis cedex - France)","institution_ids":["https://openalex.org/I1902872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045703478","display_name":"Olivier Levillain","orcid":"https://orcid.org/0000-0002-0558-5015"},"institutions":[{"id":"https://openalex.org/I4210145102","display_name":"Institut Polytechnique de Paris","ror":"https://ror.org/042tfbd02","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210145102"]},{"id":"https://openalex.org/I4387153010","display_name":"T\u00e9l\u00e9com SudParis","ror":"https://ror.org/05xvk4r52","country_code":"FR","type":"education","lineage":["https://openalex.org/I205703379","https://openalex.org/I4210145102","https://openalex.org/I4387153010"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Olivier Levillain","raw_affiliation_strings":["Institut Polytechnique de Paris, Palaiseau, France","Samovar, Evry, France","T\u00e9l\u00e9com SudParis, Evry, France","IP Paris - Institut Polytechnique de Paris (Route de Saclay, 91120 Palaiseau Cedex, France - France)"],"affiliations":[{"raw_affiliation_string":"Institut Polytechnique de Paris, Palaiseau, France","institution_ids":["https://openalex.org/I4210145102"]},{"raw_affiliation_string":"Samovar, Evry, France","institution_ids":[]},{"raw_affiliation_string":"T\u00e9l\u00e9com SudParis, Evry, France","institution_ids":["https://openalex.org/I4210145102","https://openalex.org/I4387153010"]},{"raw_affiliation_string":"IP Paris - Institut Polytechnique de Paris (Route de Saclay, 91120 Palaiseau Cedex, France - France)","institution_ids":["https://openalex.org/I4210145102"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009355477","display_name":"Aur\u00e9lien Francillon","orcid":"https://orcid.org/0000-0003-0584-8732"},"institutions":[{"id":"https://openalex.org/I1902872","display_name":"EURECOM","ror":"https://ror.org/00sse7z02","country_code":"FR","type":"education","lineage":["https://openalex.org/I1902872","https://openalex.org/I205703379"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Aur\u00e9lien Francillon","raw_affiliation_strings":["EURECOM, Biot, France","Eurecom [Sophia Antipolis] (Campus SophiaTech, 450 Route des Chappes, CS 50193 - 06904 Biot Sophia Antipolis cedex - France)"],"affiliations":[{"raw_affiliation_string":"EURECOM, Biot, France","institution_ids":["https://openalex.org/I1902872"]},{"raw_affiliation_string":"Eurecom [Sophia Antipolis] (Campus SophiaTech, 450 Route des Chappes, CS 50193 - 06904 Biot Sophia Antipolis cedex - France)","institution_ids":["https://openalex.org/I1902872"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5022574838","display_name":"Rapha\u00ebl Troncy","orcid":"https://orcid.org/0000-0003-0457-1436"},"institutions":[{"id":"https://openalex.org/I1902872","display_name":"EURECOM","ror":"https://ror.org/00sse7z02","country_code":"FR","type":"education","lineage":["https://openalex.org/I1902872","https://openalex.org/I205703379"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Raphael Troncy","raw_affiliation_strings":["EURECOM, Biot, France","EURECOM (BP 193 F-06904 Sophia Antipolis cedex - France)"],"affiliations":[{"raw_affiliation_string":"EURECOM, Biot, France","institution_ids":["https://openalex.org/I1902872"]},{"raw_affiliation_string":"EURECOM (BP 193 F-06904 Sophia Antipolis cedex - France)","institution_ids":["https://openalex.org/I1902872"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5087943069"],"corresponding_institution_ids":["https://openalex.org/I1902872"],"apc_list":null,"apc_paid":null,"fwci":1.4128,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.82093174,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"35","last_page":"48"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11181","display_name":"Advanced Data Storage Technologies","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11181","display_name":"Advanced Data Storage Technologies","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9936000108718872,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.98089998960495,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.8362326622009277},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7892303466796875},{"id":"https://openalex.org/keywords/computer-graphics","display_name":"Computer graphics (images)","score":0.3968556821346283},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.10766318440437317}],"concepts":[{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.8362326622009277},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7892303466796875},{"id":"https://openalex.org/C121684516","wikidata":"https://www.wikidata.org/wiki/Q7600677","display_name":"Computer graphics (images)","level":1,"score":0.3968556821346283},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.10766318440437317}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3634737.3637654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637654?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-04446027v1","is_oa":true,"landing_page_url":"https://hal.science/hal-04446027","pdf_url":"https://hal.science/hal-04446027v1/document","source":{"id":"https://openalex.org/S4406922461","display_name":"SPIRE - Sciences Po Institutional REpository","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"The 19th ACM ASIA Conference on Computer and Communications Security (ACM ASIACCS), ACM, Jul 2024, Singapore, Singapore. pp.35-48, &#x27E8;10.1145/3634737.3637654&#x27E9;","raw_type":"Conference papers"}],"best_oa_location":{"id":"doi:10.1145/3634737.3637654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637654?download=true","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10","score":0.4099999964237213}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4400121414.pdf","grobid_xml":"https://content.openalex.org/works/W4400121414.grobid-xml"},"referenced_works_count":14,"referenced_works":["https://openalex.org/W2095519872","https://openalex.org/W2139321017","https://openalex.org/W2233063544","https://openalex.org/W2261444101","https://openalex.org/W2324374191","https://openalex.org/W2545990795","https://openalex.org/W2558503915","https://openalex.org/W2884216354","https://openalex.org/W3081194266","https://openalex.org/W4242464041","https://openalex.org/W4296962513","https://openalex.org/W4307020345","https://openalex.org/W4385208592","https://openalex.org/W4385270098"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W4230197055","https://openalex.org/W4296749040","https://openalex.org/W621808327","https://openalex.org/W644007644","https://openalex.org/W2497198634","https://openalex.org/W3012257603","https://openalex.org/W1586784764","https://openalex.org/W4292264782"],"abstract_inverted_index":{"While":[0],"internet":[1,23],"communications":[2],"have":[3],"been":[4],"originally":[5],"all":[6],"in":[7,49],"the":[8,10,99,159,195],"clear,":[9],"past":[11],"decade":[12],"has":[13],"seen":[14],"secure":[15],"protocols":[16],"like":[17],"TLS":[18,71,76,78,112,116,130,145,165,188],"becoming":[19],"pervasive,":[20],"significantly":[21,157],"improving":[22],"security":[24,57,173],"for":[25,35,183,190],"individuals":[26],"and":[27,38,80,90,136,149],"enterprises.":[28],"However,":[29],"encrypted":[30],"traffic":[31,166],"raises":[32],"new":[33,69],"challenges":[34],"intrusion":[36],"detection":[37,196],"network":[39],"monitoring.":[40],"Existing":[41],"interception":[42],"solutions":[43],"such":[44,132,185],"as":[45,133,186],"Man-In-The-Middle":[46],"are":[47,59],"undesirable":[48],"many":[50],"settings:":[51],"they":[52],"tend":[53],"to":[54,61,163,193],"lower":[55],"overall":[56],"or":[58,96,175],"challenging":[60],"use":[62,181],"at":[63,106],"scale.":[64,107],"We":[65,140,153,178],"present":[66],"X-Ray-TLS,":[67,184],"a":[68,94,122,150],"target-agnostic":[70],"decryption":[72,189],"method":[73,83],"that":[74,155],"supports":[75],"1.2,":[77],"1.3,":[79],"QUIC.":[81],"Our":[82],"relies":[84],"only":[85],"on":[86,110,143],"existing":[87],"kernel":[88],"facilities":[89],"does":[91],"not":[92],"require":[93],"hypervisor":[95],"modification":[97],"of":[98,167,197],"target":[100],"programs,":[101],"making":[102],"it":[103],"easily":[104],"applicable":[105],"X-Ray-TLS":[108,142,156],"works":[109,128],"major":[111,144],"libraries":[113],"by":[114],"extracting":[115],"secrets":[117],"from":[118],"process":[119],"memory":[120,123],"using":[121],"changes":[124],"reconstruction":[125],"algorithm.":[126],"It":[127],"with":[129],"hardening,":[131],"certificate":[134],"pinning":[135],"perfect":[137],"forward":[138],"secrecy.":[139],"benchmark":[141],"libraries,":[146],"CLI":[147],"tools,":[148],"web":[151],"browser.":[152],"show":[154],"reduces":[158],"manual":[160],"effort":[161],"required":[162],"decrypt":[164],"programs":[168],"running":[169],"locally,":[170],"thus":[171],"simplifying":[172],"analysis":[174],"reverse":[176],"engineering.":[177],"identified":[179],"several":[180],"cases":[182],"large-scale":[187],"CI/CD":[191],"pipelines":[192],"support":[194],"software":[198],"supply":[199],"chain":[200],"attacks.":[201]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-25T14:56:36.534964","created_date":"2025-10-10T00:00:00"}
