Detecting network attacks based on quantum-safety of connections
A processing device is configured to detect potential encryption downgrades in network communications. The processing device accesses network traffic and detects an attempted first connection between a first entity and a second entity in which the first entity offered at least one post-quantum cryptography (PQC) algorithm to encrypt the attempted first connection. The method detects that the attempted first connection failed, and that a second connection between the first entity and the second entity successfully completed without a PQC algorithm, within a threshold time after the attempted first connection. The processing device identifies this second detection as a downgrade attack and performs a remedial action.
1 . A method, performed by a processing device, comprising:
accessing network traffic;
detecting, in the network traffic, an attempted first connection between a first entity and a second entity in which the first entity offered at least one post-quantum cryptography (PQC) algorithm to encrypt the attempted first connection;
detecting, in the network traffic, that the attempted first connection failed;
detecting, in the network traffic, that a second connection between the first entity and the second entity successfully completed a handshake, occurred within a threshold time after the attempted first connection, and was established without a PQC algorithm; and
performing a remedial action, in accordance with detecting that the second connection between the first entity and the second entity established without the PQC algorithm within the threshold time after the attempted first connection, wherein the remedial action comprises at least filtering or blocking a future message to or from the first entity.
2 . The method of claim 1 , wherein determining that the second connection was established without the PQC algorithm comprises comparing a negotiated algorithm identified in a handshake message of the second connection to a list indicating PQC algorithms or non-PQC algorithms or both.
3 . The method of claim 1 , wherein detecting the attempted first connection comprises comparing one or more algorithms identified in a handshake message to a list indicating PQC algorithms or non-PQC algorithms or both, to determine that the first entity offered the at least one PQC algorithm.
4 . The method of claim 1 , wherein the remedial action further comprises at least one of:
displaying an indication that the first entity has experienced a cybersecurity attack, or
transmitting an alert indicating that the first entity has experienced the cybersecurity attack.
5 . The method of claim 1 , further comprising increasing the threshold time in response to a number of detected downgrade connections exceeding a threshold.
6 . The method of claim 1 , further comprising:
storing a profile associated with a plurality of past connections of the first entity;
detecting, in the network traffic, a third connection between the first entity and a third entity; and
comparing an algorithm used to establish the third connection to the plurality of past connections of the profile to determine that a condition is satisfied; and
performing a second remedial action, in accordance with when the condition is satisfied.
7 . The method of claim 6 , wherein the profile comprises, for each of the plurality of past connections, a source, a destination, an application-layer protocol, a first count of quantum-safe connections made between the source and the destination using the application-layer protocol, and a second count of quantum-unsafe connections made between the source and the destination.
8 . The method of claim 7 , wherein the condition is satisfied when the algorithm of the third connection is a non-PQC algorithm and when the first count is below a threshold.
9 . The method of claim 7 , wherein the condition is satisfied when the algorithm of the third connection is a non-PQC algorithm and when the first count is greater than the second count by a threshold amount.
10 . The method of claim 7 , further comprising updating the profile to store the plurality of past connections with: only most-recent N connections; or only connections within a sliding time window.
11 . A system, comprising:
a memory; and
a processing device, operatively coupled to the memory, to:
access network traffic;
detect, in the network traffic, an attempted first connection between a first entity and a second entity in which the first entity offered at least one post-quantum cryptography (PQC) algorithm to encrypt the attempted first connection;
detect, in the network traffic, that the attempted first connection failed;
detect, in the network traffic, that a second connection between the first entity and the second entity successfully completed a handshake, occurred within a threshold time after the attempted first connection, and was established without a PQC algorithm; and
perform a remedial action, in accordance with detecting that the second connection between the first entity and the second entity established without the PQC algorithm within the threshold time after the attempted first connection, wherein the remedial action comprises at least filtering or blocking a future message to or from the first entity.
12 . The system of claim 11 , wherein to determine that the second connection was established without the PQC algorithm comprises to compare a negotiated algorithm identified in a handshake message of the second connection to a list indicating PQC algorithms or non-PQC algorithms or both.
13 . The system of claim 11 , wherein to detect the attempted first connection comprises:
to compare one or more algorithms identified in a handshake message to a list indicating PQC algorithms or non-PQC algorithms or both, to determine that the first entity offered the at least one PQC algorithm.
14 . The system of claim 13 , wherein the processing device is further to:
store a profile associated with a plurality of past connections of the first entity;
detect, in the network traffic, a third connection between the first entity and a third entity; and
compare an algorithm used to establish the third connection to the plurality of past connections of the profile to determine that a condition is satisfied; and
perform a second remedial action, in accordance with when the condition is satisfied.
15 . The system of claim 14 , wherein the profile comprises, for each of the plurality of past connections, a source, a destination, an application-layer protocol, a first count of quantum-safe connections made between the source and the destination using the application-layer protocol, and a second count of quantum-unsafe connections made between the source and the destination.
16 . A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:
access network traffic;
detect, in the network traffic, an attempted first connection between a first entity and a second entity in which the first entity offered at least one post-quantum cryptography (PQC) algorithm to encrypt the attempted first connection;
detect, in the network traffic, that the attempted first connection failed;
detect, in the network traffic, that a second connection between the first entity and the second entity successfully completed a handshake, occurred within a threshold time after the attempted first connection, and was established without a PQC algorithm; and
perform a remedial action, in accordance with detecting that the second connection between the first entity and the second entity established without the PQC algorithm within the threshold time after the attempted first connection, wherein the remedial action comprises at least filtering or blocking a future message to or from the first entity.
17 . The non-transitory computer readable medium of claim 16 , wherein to determine that the second connection was established without the PQC algorithm comprises to compare a negotiated algorithm identified in a handshake message of the second connection to a list indicating PQC algorithms or non-PQC algorithms or both.
18 . The non-transitory computer readable medium of claim 16 , wherein to detect the attempted first connection comprises:
to compare one or more algorithms identified in a handshake message to a list indicating PQC algorithms or non-PQC algorithms or both, to determine that the first entity offered the at least one PQC algorithm.
19 . The non-transitory computer readable medium of claim 18 , wherein the processing device is further to:
store a profile associated with a plurality of past connections of the first entity; detect, in the network traffic, a third connection between the first entity and a third entity; and
compare an algorithm used to establish the third connection to the plurality of past connections of the profile to determine that a condition is satisfied; and
perform a second remedial action, in accordance with when the condition is satisfied.
20 . The non-transitory computer readable medium of claim 19 , wherein the profile comprises, for each of the plurality of past connections, a source, a destination, an application-layer protocol, a first count of quantum-safe connections made between the source and the destination using the application-layer protocol, and a second count of quantum-unsafe connections made between the source and the destination.