P4-TLSfp: Passive TLS Fingerprinting Using P4-Enabled Programmable Data Plane Switches
E Vasudha, Krishna Moorthy Sivalingam, Gauravdeep Shami · 2025
TLS fingerprinting aids network operators to identify TLS clients running on the hosts communicating to their network. This helps them to identify vulnerable clients which could pose a security threat to their network in the future as they might have an underlying outdated TLS library. This information can be used by them to block or redirect the traffic. Existing software approaches cannot keep up with highspeed networks. This paper presents a P4-based programmable data plane implementation of TLS fingerprinting, based on JA3 scheme, and referred to as P4-TLSfp. P4-TLSfp runs on Tofino switches at line rate to perform fingerprinting and is used to identify the security profile of the clients. Experiments on packets collected from TLS/SSL clients running inside a campus network were conducted. The experimental results show that P4-TLSfp takes approximately 783 ns on the Intel Tofino switch translating to a throughput of$\mathbf{1. 3 2}$Mpps, whereas the JA3, implemented on server, takes approximately$300 \mu \mathrm{s}$.