
Today, secure internet traffic via the HTTPS protocol (HyperText Transfer Protocol Secure) is becoming widespread, now accounting for more than 80% of web traffic in France and likely to reach 90% by 2020. This growth reflects a fundamental trend toward securing data exchanges. It also responds to Google's initiative to favor the natural referencing of HTTPS websites in its search engine and penalize those that are not.
This transformation can be seen at all levels, as almost all web browsers now consider access to an unencrypted HTTP site to be dangerous and warn users with explicit alerts.
However, the explosion in secure internet traffic does not simplify the task of HTTPS filtering for CIOs and CISOs, who face a real technical headache with SSL/TLS decryption and a legal one, since the company is not authorized to decrypt all traffic (in the banking or healthcare sectors, for example). Analyzing the traffic exchanged between the company's internal network and the outside world is vital for web security and information system protection. So what are the recommendations for addressing this new HTTPS requirement?
Understanding the nature of HTTPS traffic for corporate web security
The HTTPS protocol complements the traditional HTTP protocol with an additional layer of security that allows secure information to be exchanged over a TCP/IP network. This additional layer corresponds to the TLS (Transport Layer Security) protocol, which is a newer and, above all, more secure version of the better-known SSL (Secure Socket Layer) protocol.
When HTTP traffic is encapsulated in the TLS protocol, this guarantees both the confidentiality and integrity of communications from the server to connected client workstations, while also ensuring their authentication. All parties involved can therefore be sure that the information exchanged cannot be tampered with: the website being viewed is indeed the one expected, and users can safely provide their credit card numbers and/or personal information.
With cyber threats on the rise, it's clear that the widespread use of secure web connections is a positive trend, both for individuals and businesses. But IT security specialists are under no illusions: even if data flows are encrypted, they can still pose hidden risks! Hackers can attempt to hide their malware in these flows, and certain HTTPS URLs can obviously be malicious. That is why it is now essential to enhance traditional security measures in order to decrypt these flows and verify that there are no threats within them.
HTTPS filtering: essential TLS/SSL decryption
To address these hidden risks and help organizations protect their information systems, ANSSI has issued recommendations. However, since the TLS protocol provides security and confidentiality for exchanges, "breaking" this protection is not necessarily easy from a technical standpoint, nor is it free from legal obligations that must be respected.
Obviously, a whitelist that only allows browsing to recognized and pre-qualified URLs would be an excellent way to protect against potential threats, but it is not necessarily applicable in all sectors of activity. It is therefore sometimes necessary to decrypt...
To ensure secure communication, the mechanism used in HTTPS exchanges relies on authentication using a certificate associated with the website, which is verified by the client's browser, as well as the exchange of public and private keys. The public key (accessible to everyone) is used to encrypt data, while only the private key can be used to decrypt it.
In order to intercept this secure communication, the web security gateway must use the MITM or "Man in the middle" technique by validating the certificate itself and establishing a connection where it acts as a sort of proxy for the user. The web security gateway will therefore reform the communication using certificates without breaking the security chain: the user continues to access the website securely, but the gateway can verify the nature of the content being exchanged. To do this, it must integrate an HTTPS (SSL) decryption pack, such as the one we offer at Olfeo.
The goal is obviously to block any potential threat as early as possible, before it reaches the end user's workstation, which is increasingly targeted by cybercriminals. It is also essential to develop a better security culture among end users and change behaviors.
The limits of SSL decryption and HTTPS content filtering
HTTPS filtering and SSL decryption obviously raise issues of technical optimization, rights, and obligations. The first requirement is obviously to guarantee the highest level of security and confidentiality around the web security gateway, which will process data that is normally encrypted and therefore potentially confidential.
Secondly, SSL decryption consumes machine resources; best practice therefore involves setting up exceptions for certain types of traffic, such as that generated by authorized business software. This allows decryption efforts to be focused on other types of traffic, such as YouTube, social networks, webmail, etc.
In fact, decrypting these flows is sometimes essential in view of the obligations incumbent on the company in terms of legal and cultural compliance when surfing the internet: YouTube videos may offer tutorials on how to make homemade grenades or give access to very violent images, and this type of browsing cannot be accepted in the company. However, it is also prohibited to decrypt traffic related to browsing certain websites, such as when a user visits their bank or insurance company's website or accesses the AMELI portal, as personal data may be exchanged in such cases.
Legal compliance requirements for SSL decryption are therefore crucial and are set out in the ANSSI technical note. You must therefore ensure that your proxy is compliant and meets these obligations, as we do at Olfeo.
HTTPS filtering: the essential integration of the standalone proxy with the UTM
Finally, for your HTTPS filtering strategy to be truly effective, you must choose the right tools and not rely solely on UTM (Unified Threat Management) and/or Firewall for SSL decryption. We now know that SSL decryption on a firewall can result in performance losses of up to 74% (NSS Labs, John W. Pirc, Significant SSL performance loss leaves much room for improvement), so it is essential to add a standalone proxy to your firewall.
For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.
The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.
For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.
The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.
Web filtering remains one of the pillars of a cybersecurity strategy, and UTM cannot do everything (well).
Today, we can no longer be complacent about cybersecurity. Attacks are inevitable, and malware can disrupt business operations, as was the case this year for the Fleury Michon agri-food group, which was hit hard enough to have to disconnect all of its systems to prevent the threat from spreading. Web filtering and SSL-TLS decryption of HTTPS traffic, which help to better detect malicious code, are therefore essential for an effective cybersecurity strategy.
Furthermore, we must not forget the legal and liability issues associated with internet use, which are part of the challenges of web filtering. UTMs based on international categories do not offer the same level of quality as our URL database, which has been built up by a French team over the past 16 years. The result is often that the lack of precision in the categories and URLs leads to certain sites being blocked unfairly because they have been incorrectly classified by robots. With Olfeo, the Pornic town hall website or the Paris-Expo website will not be classified as pornography, and a doctor researching the male reproductive system will not be blocked. On the contrary, there are many different categories in Olfeo, and the granularity of the URLs is highly appreciated by our customers for customizing their user rules.


