Group Purchasing
Group Purchasing

Evaluating Modern Network Protocol Fingerprinting: Defending Bastion Hosts in Hostile Networks

Evaluating Modern Network Protocol Fingerprinting: Defending Bastion Hosts in Hostile Networks (PDF, 1.15MB)Published: 06 Feb, 2025
Created by:
Christopher Carroll

Adversaries continue to attack the network perimeter and trusted user workstations to gain access to sensitive networks. Modern networks are designed and often mandated to use encrypted communication paths everywhere. Once inside the trusted network, credential theft can enable adversaries to penetrate further and gain access to sensitive data.

Bastion hosts can be used to strengthen security and prevent unauthorized access. Bastion hosts may be the next target once an adversary gains initial access to a network. Many organizations rely on hardened Bastion host configurations and host-based security solutions to detect, deny, and disrupt adversarial activity. Modern network protocol fingerprinting can provide meaningful out-of-band insight into encrypted connections, shifting the advantage to network defenders.