Learn · Network forensics

DNS, HTTP & TLS

Three protocols cover most of what a user does on the web: a name lookup, a request, and the encryption around it. Even when the content is encrypted, each leaves traces that an investigator can read.

1 DNS: a question and an answer

Before a client connects to www.example.org it asks a resolver for the address, usually over UDP port 53. Query and answer share a 2-byte transaction ID. Names are stored as labels: a length byte, then that many characters, ending with a zero byte. www.example.org becomes 03 77 77 77 07 65 78 61 6D 70 6C 65 03 6F 72 67 00.

The answer repeats the question and adds a resource record. Its name is just C0 0C: a compression pointer (top two bits set) to offset 12 of the DNS message, where the question's name starts. The record also carries a TTL: how long caches may keep it.

Forensic value: DNS logs show intent (a client wanted to reach a name) even if the connection was later blocked. But mind who asks: behind a proxy or a forwarding resolver, the log shows the proxy or resolver as the client, not the user's PC. Caching hides repeat visits for the TTL.

2 HTTP: plain text on the wire

Unencrypted HTTP is readable line by line: a request line (method, path, version), headers, an empty line, an optional body. The Host header names the site; User-Agent names the client software, which helps to tell a browser from a script or an update service.

Plain HTTP is rare for websites today, but common for update checks, telemetry, internal devices, printers and old applications. Whatever travels in plain HTTP (query strings, cookies, form fields) is visible to every capture point and in every proxy log.

3 Through a proxy

In companies, browsers often talk to an explicit proxy instead of the server. The request line then changes:

GET http://www.example.org/index.html HTTP/1.1 ← plain HTTP: full URL, the proxy fetches it CONNECT shop.example.net:443 HTTP/1.1 ← HTTPS: "open a tunnel to this host and port" Proxy-Authorization: Negotiate YIIH… ← Kerberos/NTLM: the proxy learns the Windows user

For HTTPS the proxy sees only the host and port in the CONNECT line, then relays encrypted bytes. Unless it does TLS inspection (decrypting with a company certificate), its log has no path, no file name, no content, only the volume in each direction and the duration. Many companies exclude categories such as banking, health or personal webmail from inspection for privacy reasons; the proxy configuration tells you which.

Proxy logs usually write one line per request when it ends. A tunnel that stayed open for 20 minutes appears at its end time, with the duration in a separate field. Subtract it to get the start.

4 TLS: what encryption leaves visible

A TLS connection starts with a ClientHello in clear text. It contains the SNI (server name indication: the host name the client wants), the protocols it can speak inside (ALPN: h2, http/1.1), and long lists of cipher suites and extensions that differ between browsers, libraries and tools.

The JA3 fingerprint is an MD5 hash over the ClientHello's version, cipher suites, extensions, groups and point formats. The same software produces the same JA3, so it can link connections made by the same client program, or show that "the browser" was in fact a script. It does not identify a person. (JA4 is a newer, more robust variant.)

Visible without decryptionHidden
Client and server addresses and ports; start, end, durationURL path and query, headers, cookies
SNI host name (unless Encrypted Client Hello is used)Request and response bodies, file names
ClientHello fingerprint (JA3/JA4), ALPNIn TLS 1.3: the server certificate
Record sizes and timing: uploads vs downloads, burstsWhich of several sites on the same server was used, if SNI is absent

Direction and volume tell a lot: a session where the client sends hundreds of megabytes and receives a few kilobytes is an upload, whatever the content. Watch out for DNS over HTTPS (lookups hidden inside HTTPS), QUIC (HTTP/3 over UDP 443) and Encrypted Client Hello, which remove some of these traces.

5 Try it yourself

Answer from the hex views above.

Which two bytes link the DNS answer to its query (the transaction ID)? Type them in file order.

The DNS message starts right after the 8-byte UDP header; the ID is its first field.

1A 2B in both packets. A resolver that gets an answer with an unknown ID throws it away; that is part of the protection against forged answers.

For how many seconds may a cache keep the answer for www.example.org?

The TTL is the 4-byte field after type and class in the answer record.

00 00 0E 10 = 3,600 seconds, one hour. During that hour, repeat lookups by clients of the same resolver do not reach the upstream servers, so upstream DNS logs undercount visits.

Which host name does the TLS client ask for (SNI)?

Look for the extension of type 00 00 in the ClientHello.

shop.example.net. The extension holds a list with one entry: type 0 (host name), length, and the name in ASCII. A proxy or firewall that cannot decrypt can still log this name.

A user downloads https://shop.example.net/orders/2026.pdf through an explicit proxy without TLS inspection. What can the proxy log?

Compare the two request lines in section 3.

The browser sends CONNECT shop.example.net:443; the path travels only inside TLS. The proxy logs host, port, user, bytes and duration. With TLS inspection enabled it could log the full URL.

These are the query name and the type/class of the DNS query. Edit them and watch the decoded query:

  • Change the first length byte 03 to 02. Where does the decoder now split the name, and why does everything after it shift?
  • Reset, then change the type (00 01) to 00 1C. What is the client asking for now?