Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0339 — Detection Strategy for Weaken Encryption on Network Devices
DET0339

Detection Strategy for Weaken Encryption on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0961 Analytic 0961
Network Devices

Defenders may observe unauthorized modifications to encryption-related configuration files, firmware, or crypto modules on network devices. Suspicious patterns include changes to cipher suite configurations, unexpected firmware updates affecting crypto libraries, disabling of hardware cryptographic accelerators, or reductions in key length policies. Correlating configuration changes with anomalies in encrypted traffic characteristics (e.g., weaker ciphers or sudden plaintext transmission) strengthens detection.

networkdevice:config Configuration change events referencing encryption, TLS/SSL, or IPSec settings NSM:Flow Traffic patterns showing downgrade from strong encryption (AES-256) to weaker or plaintext protocols snmp:status Status change in cryptographic hardware modules (enabled -> disabled)
[CipherSuiteWhitelist] List of approved encryption algorithms and key lengths; customizable to organizational policy.
[TimeWindow] Correlation period between configuration changes and abnormal traffic; adjustable to reduce false positives.
[AuthorizedFirmwareSources] Known trusted sources of firmware updates; deviations indicate possible compromise.
[TrafficEntropyThreshold] Baseline entropy measurements of encrypted traffic; deviations may reveal weakening of encryption.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0339
STIX ID
x-mitre-detection-strategy--de98fda3-10f9-4013-a163-fb9b6c117a9b
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.