SSL Inspection (TLS Interception)
Definition
A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using a certificate signed by a CA that the client trusts. Used in enterprise environments to enforce security policy on encrypted traffic. Also called a man-in-the-middle proxy when performed without the endpoint's knowledge.
- Mechanism
- Intermediary terminates and re-encrypts the TLS session
- Trust basis
- CA certificate the client already trusts
- Common setting
- Enterprise network security policy
- Covert form
- Called a man-in-the-middle proxy
Common questions
How does SSL inspection leave forensic evidence on an endpoint?+
The intercepting device's certificate must be installed in the client's trust store, so its presence there, along with proxy logs, is often the clearest indicator that traffic was decrypted and inspected in transit.
What is the legal distinction between authorised SSL inspection and a malicious TLS interception attack?+
Authorised inspection relies on a certificate the organisation deliberately installed with the user's knowledge or consent under policy, while a malicious interception relies on a forged or improperly trusted certificate the victim never knowingly accepted.
Related terms
- Flow Record
- A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count...
- JA3 Fingerprint
- An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
- Server Name Indication (SNI)
- A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
- SSLKEYLOGFILE
- A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...
- Traffic Fingerprinting
- The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...