International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 22 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The importance of inspecting encrypted traffic

by The Gurus
April 23, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

Many adversaries to enterprise cybersecurity are using sophisticated encryption tactics to bypass defences and infiltrate networks. Enterprises are trying to fight back by employing HTTPS and using SSH, as well as other advanced protocols for data exfiltration. SSH, for example, is often used for remote management access because it performs well. But, when nearly 70 percent of all enterprise traffic is encrypted, understanding what’s hiding inside that traffic is imperative. So, what can you do to inspect that traffic?

 

The first step is to come up with an enterprise threat model so that you can easily look at and assess a threat, then outline the techniques that your adversaries are going to use. For example, The Mitre corporation developed one that they call attack matrix and as you go through and look at the attack matrix it will outline techniques that are used for exfiltration of data, command and control for remote adversaries to control malware. When you look at this and then look across at your own network you may see that you have a firewall, an IDS and an advanced threat protection, which is all good to have. However, if 60-70% of the traffic you get is encrypted then what use are these security measures at monitoring this? Enterprises need a plan in place to monitor encrypted traffic as well.

 

The next step involves utilising an advanced data exfiltration protocol, such as SSH. SSH is great and is oftentimes used for remote management access because it performs so well. RDP, Remote Desktop Protocol, is another protocol that many enterprises utilise to great effect so, in order to figure out what is best for your enterprise it’s important to consider your threat enterprise model that was discussed above. How does your model aim to inspect traffic and which software are you utilising? Some programs out there only allow you to focus on one protocol at a time while other can inspect everything from SSH to RDP to HTTPS. Which software your enterprise is using will affect what steps you need to take to monitor encrypted traffic.

 

If you’ve followed everything so far then you should be utilising an IPS, IDS, ATP and be using something akin to the Mitre attack template to evaluate your cybersecurity, which may seem like a lot, but as any cybersecurity expert will tell you: ‘there is no such thing as too much protection.’ So what type of issues might you need to still account for?

 

Well let’s assume you have a next-generation firewall and you are performing decryption at then suddenly you hit a performance bottleneck. This bottleneck would likely be caused by advanced threat protection detecting problems that are different than what your next-generation firewalls going to detect, which will be different than your IDS, and so on. All these programs detecting different problems all at the same time will likely incur latency because these are all happening at once. However, there are single devices out there that can do all of these tasks solo which will help improve performance, reducing the chance of a bottleneck creating less of a chance that your users are going to even be aware that you’re performing this inspection.

 

You may also have the issue of employee negligence or ignorance among your IT staff. Last year a report from the Ponemon Institute found that 37% of enterprises hand over their encryption duties to their cloud providers, taking an off-hand approach and rely on someone one else to do such an important job for them. Then separately a survey by Venafi found that 23 percent of their respondents had no idea how much of their encrypted traffic is decrypted and inspected. By passing off responsibility to an outside business and not properly tracking encryption in the business, many enterprises are opening themselves up outside threats, even if they have the latest technology.

 

To conclude, with at least 70 percent of all traffic encrypted it is important that enterprises are aware of everything that is hiding amongst this traffic or they risk cyber threats sneaking through. In order to achieve this, a good cyber threat model is needed as well as utilising an advanced data exfiltration protocol, like SSH. It is imperative that once you have the model in place that you have some technology that can help to easily manage it all and not be met with a performance bottleneck. Finally, it is key that all of the staff in your IT department is fully aware of exactly what is encrypted and heavily monitoring it as frequently as possible. With all of this in place, your enterprise should be fully prepared to keep your business safe from threats hiding within encrypted traffic.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Cyber Security Agency Eskenzi PR wins a Queen’s Award for Enterprise 2018

Next Post

Positive Technologies uncovers critical vulnerabilities in APC uninterrupted power supplies

Recent News

privileged access management

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

July 21, 2026
Forescout 2026 H1 Threat Review

Forescout Report Reveals Surge in AI-Driven Cyber Threats

July 21, 2026
secure-software-supply-chain-feature

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

July 21, 2026
partnership

DigiCert expands its EMEA channel strategy with Ignition Technology

July 21, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol