LoFP LoFP / legacy internal applications, industrial control systems, or embedded devices may still require deprecated tls versions or weak ciphers. exclude known legacy destination ips or subnets after validation.

Techniques

Sample rules

Deprecated TLS Version or Weak Cipher Negotiated Externally

Description

Identifies successful outbound TLS sessions that negotiate deprecated protocol versions (SSLv3, TLS 1.0, or TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Adversaries-in-the-middle and legacy malware often force these negotiations to decrypt or intercept traffic. Modern clients and services should negotiate TLS 1.2 or 1.3 with strong ciphers on internet-bound connections.

Detection logic

data_stream.dataset:network_traffic.tls
  and network.protocol: tls
  and network.transport: tcp
  and tls.established: true
  and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16)
  and not destination.ip:(
    10.0.0.0/8 or
    100.64.0.0/10 or
    127.0.0.0/8 or
    169.254.0.0/16 or
    172.16.0.0/12 or
    192.0.0.0/24 or
    192.0.0.0/29 or
    192.0.0.10/32 or
    192.0.0.170/32 or
    192.0.0.171/32 or
    192.0.0.8/32 or
    192.0.0.9/32 or
    192.0.2.0/24 or
    192.168.0.0/16 or
    192.175.48.0/24 or
    192.31.196.0/24 or
    192.52.193.0/24 or
    192.88.99.0/24 or
    198.18.0.0/15 or
    198.51.100.0/24 or
    203.0.113.0/24 or
    224.0.0.0/4 or
    240.0.0.0/4 or
    "::1" or
    "FE80::/10" or
    "FF00::/8"
  )
  and (
    tls.version:(1.0 or 1.1) or
    (tls.version_protocol:ssl and tls.version:3.0) or
    (
      not tls.version:1.3 and (
        tls.cipher:(
          *RC4* or
          *3DES* or
          *NULL* or
          *EXPORT* or
          *_anon_* or
          *ADH* or
          *AECDH*
        )
      )
    )
  )