Towards Internet-Based State Learning of TLS State Machines
Marcel Maehren, Nurullah Erinola, Robert Merget, Jörg Schwenk, Juraj Somorovsky
34th USENIX Security Symposium · Day 1
This paper presents a groundbreaking approach to understanding the real-world behavior of Transport Layer Security (TLS) implementations by applying **state machine learning (SML)** techniques at an unprecedented scale over the Internet. Traditionally, SML has been confined to controlled, local environments where network conditions are stable, and implementation details are often known or modifiable. The authors, a team of researchers from Ruhr University Bochum, Technology Innovation Institute, and Paderborn University, challenge this paradigm by addressing the inherent complexities of the Internet, such as non-determinism, network jitter, and unknown server configurations.
AI review
Solid systems security work that actually delivers on its promise: SML at Internet scale, with real bugs found. The Citrix transcript integrity flaw and the padding oracle detections justify the paper. Not revolutionary technique-wise, but the engineering to make this work in the wild is non-trivial and the results speak for themselves.