System and method for observing encrypted traffic in java applications using eBPF and JAVA agent
A method for observing encrypted traffic in a Java applications is disclosed. The method includes providing the eBPF program to capture to capture encrypted data from kernel-level read and write operations, and/or Transfer Layer Security (TLS) generated key. The method also includes providing a Java agent to instrument functions involved in TLS key generation and to extract session secrets. Further, the method includes facilitating the Java agent to write session secrets to a non-persistent storage medium, such that the eBPF program reads session secrets from the non-persistent storage medium. Thereafter, the method includes providing a user-space program to receive the encrypted data and session secrets from the eBPF program and decrypt the data for analyzing and tracing the Java application.
1 . A system for observing encrypted traffic in a Java application, the system comprising:
one or more processors; and
a memory storing instructions that, when executed by the one or more processors, cause the system to:
capture, by an extended Berkeley Packet Filter (eBPF) program, encrypted data from kernel-level read and write operations associated with the Java application;
instrument, by a Java agent, functions involved in Transfer Layer Security (TLS) key generation;
extract, by the Java agent, session secrets from the functions;
write, by the Java agent, the session secrets to a non-persistent storage medium;
capture, by the eBPF program, the session secrets from a kernel-level write operation directed to the non-persistent storage medium;
receive, by a user-space program and from the eBPF program, the encrypted data and the session secrets; and
decrypt, by the user-space program, the encrypted data for analyzing and tracing the Java application.
2 . The system of claim 1 , wherein the non-persistent storage medium is associated with “/dev/null”.
3 . The system of claim 1 , wherein the eBPF program maintains connection state information that correlates the encrypted data with the appropriate session secrets.
4 . The system of claim 1 , wherein the Java agent corresponds to a lightweight program that instruments only the TLS key generation functions.
5 . The system of claim 4 , wherein the TLS key generation functions are part of the cryptography library and security provider used by the Java application, such that the TLS key generation functions are invoked once during initial SSL handshake of the connection.
6 . The system of claim 1 , wherein the eBPF program operates at a kernel level.
7 . The system of claim 1 , wherein the non-persistent storage medium is configured such that the session secrets are not persistently stored after the kernel-level write operation directed to the non-persistent storage medium.
8 . The system of claim 1 , wherein the user-space program further analyzes the decrypted data for at least one of: performance monitoring, security auditing, and troubleshooting purposes.
9 . A method for observing encrypted traffic in a Java application, the method comprising:
capturing, by an extended Berkeley Packet Filter (eBPF) program, encrypted data from kernel-level read and write operations associated with the Java application;
instrumenting, by a Java agent, functions involved in Transfer Layer Security (TLS) key generation;
extracting, by the Java agent, session secrets from the functions;
writing, by the Java agent, session secrets to a non-persistent storage medium;
capturing, by the eBPF program, the session secrets from a kernel-level write operation directed to the non-persistent storage medium;
receiving, by a user-space program and from the eBPF program, the encrypted data and the session secrets; and
decrypting, by the user-space program, the encrypted data for analyzing and tracing the Java application.
10 . The method of claim 9 , wherein the non-persistent storage medium is associated with “/dev/null”.
11 . The method of claim 9 , further comprising maintaining connection state information that correlates the encrypted data with the appropriate session secrets.
12 . The method of claim 9 , wherein the Java agent corresponds to a lightweight program that instruments only the TLS key generation functions.
13 . The method of claim 12 , wherein the TLS key generation functions are part of the cryptography library and security provider used by the Java application, such that the TLS key generation functions are invoked once during initial SSL handshake of the connection.
14 . The method of claim 9 , wherein the eBPF program operates at a kernel level.
15 . The method of claim 9 , wherein the non-persistent storage medium is configured such that the session secrets are not persistently stored after the kernel-level write operation directed to the non-persistent storage medium.
16 . The method of claim 9 , wherein the user-space program further analyzes the decrypted data for at least one of: performance monitoring, security auditing, and troubleshooting purposes.
17 . A computer program product including at least one non-transitory computer-readable storage medium having computer-executable program code portions stored therein, the computer program product is configured to:
capture, by an extended Berkeley Packet Filter (eBPF) program, encrypted data from kernel-level read and write operations associated with a Java application;
instrument, by a Java agent, functions involved in Transfer Layer Security (TLS) key generation;
extract, by the Java agent, session secrets from the functions;
write, by the Java agent, session secrets to a non-persistent storage medium;
capture, by the eBPF program, session secrets from a kernel-level write operation directed to the non-persistent storage medium;
receive, by a user-space program and from the eBPF program, the encrypted data and the session secrets; and
decrypt, by the user-space program, the encrypted data for analyzing and tracing the Java application.
18 . The computer program product of claim 17 ,
wherein the non-persistent storage medium is associated with “/dev/null;
wherein the Java agent corresponds to a lightweight program that instruments only the TLS key generation functions;
wherein the TLS key generation functions are part of the cryptography library and security provider used by the Java application, such that the TLS key generation functions are invoked once during initial SSL handshake of the connection;
wherein the eBPF program operates at a kernel level; and
wherein the user-space program further analyzes the decrypted data for at least one of: performance monitoring, security auditing, and troubleshooting purposes.
19 . The computer program product of claim 17 , further configured to maintain connection state information that correlates the encrypted data with the appropriate session secrets.
20 . The computer program product of claim 17 , wherein the non-persistent storage medium is configured such that the session secrets are not persistently stored after the kernel-level write operation directed to the non-persistent storage medium.