VB2016 preview: Detecting Man-in-the-Middle Attacks With Canary Requests

Posted by   Martijn Grooten on   Sep 6, 2016

While man-in-the-middle attacks are relatively rare (especially among those not attending hacker conferences), it is quite common for computer users to be in a situation where an attacker could have an opportunity to take control of their network traffic. There are, of course, network mechanisms that seriously mitigate the risk, such as VPN or HTTPS, but these aren't universally applied and can sometimes be bypassed through social engineering.

108x153-Brian-Wallace.jpgSo how do you know that your network traffic is being modified? At VB2016, Cylance researcher Brian Wallace will present a multi-platform tool that runs on the endpoint and detects (active) man-in-the-middle attacks.

Dubbed 'MITM Canary', the tool achieves this in two different ways. Firstly, it makes network requests and compares the responses in various ways with the expected response; a difference could indicate something is modifying network traffic. Secondly, it attempts to identify the methods used to launch MITM attacks, such as controlling DNS responses.

At around the time of his conference presentation, Brian will release the tool and its source code to the public.


Last year, Brian wrote two technical articles for Virus Bulletin: on the use of .NET GUIDs to find malware and on an optimization for ssDeep to make it work at scale. Both are well worth a read, especially if you are into Big Data research.

Registration for VB2016 is still open.




Latest posts:

VB2019 paper: A study of Machete cyber espionage operations in Latin America

At VB2019 in London a group of researchers from the Stratosphere Lab at the Czech Technical University in Prague presented a paper in which they analysed and dissected the cyber espionage activities of an APT group in Latin America through the…

VB2019 paper: The push from fiction for increased surveillance, and its impact on privacy

In a paper presented at VB2019 in London, researchers Miriam Cihodariu (Heimdal Security) and Andrei Bogdan Brad (Code4Romania) looked at how surveillance is represented in fiction and how these representations are shaping people's attitudes to…

VB2019 paper: Oops! It happened again!

At VB2019 in London industry veterans Righard Zwienenberg and Eddy Willems took a detailed look at the relationship between past and current cyber threats. Today, we publish both their paper and the recording of their presentation.

Job vacancy at VB: Security Evangelist

Virus Bulletin is recruiting for a person to be the public face of the company

VB2019 video: Thwarting Emotet email conversation thread hijacking with clustering

At VB2019 in London, ZEROSPAM researchers Pierre-Luc Vaudry and Olivier Coutu discussed how email clustering could be used to detect malicious Emotet emails that hijacked existing email threads. Today we publish the recording of their presentation.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.