---
title: Analysis of TLS Cipher Suite Security in Stamus App for Splunk
description: Learn how the newest version of Stamus App for Splunk can be used to conduct analysis of TLS Cipher Suite Security.
image: https://www.stamus-networks.com/hubfs/Splunk%20for%20TLS%20Cipher.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Analysis of TLS Cipher Suite Security in Stamus App for Splunk

 by [Eric Leblond](https://www.stamus-networks.com/blog/author/eric-leblond) | Nov 22, 2022 | [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Splunk](https://www.stamus-networks.com/blog/tag/splunk), [Stamus Security Platform](https://www.stamus-networks.com/blog/tag/stamus-security-platform), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs)

![](https://www.stamus-networks.com/hubfs/Splunk%20for%20TLS%20Cipher.jpg)

The latest version (1.0.1) of  the [Stamus App for Splunk](https://www.stamus-networks.com/blog/introducing-the-stamus-networks-app-for-splunk?hsLang=en) adds TLS cipher suite analysis. Conducting analysis of TLS Cipher Suites typically yields interesting results as it highlights the level of confidentiality and security of the TLS sessions. Now, Stamus App for Splunk users can quickly assess the security level of TLS used in their network from an easy-to-view dashboard. 

# TLS Cipher Suite Analysis in Stamus App For Splunk v1.0.0

TLS Cipher Suites define which algorithms will be used to encrypt communications and secure network connections. There are multiple cipher suites, and the level of security and confidentiality provided by each suite varies greatly. 

For example, “TLS_NULL_WITH_NULL_NULL” is a valid TLS cipher suite and, as the name implies, it does nothing to encrypt the communications and the data is transferred in clear text. 

While this is an extreme and unlikely case, certain TLS cipher suites should be avoided. For instance, the cipher suites that use the RC4 cipher should be avoided because the RC4 algorithm is known to have vulnerabilities and has reportedly been cracked by nation state actors since 2015.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcG2PE9Zsxoh90-yT3jtqbgEeqAY8f6MSJclHV_IFteE0qtea9VwZqoOnAYlXW89tU-d97TgIZmeZzXk2h0br24l17FIT0lVLAwj6vMqobU8bOAr6gNPKHDVa2LUbImyM3keIDEkV28HFyR10ABd5TC4WE?key=ydKSN5uwiMA9QBP589QvJVgX)

If the TLS Cipher suite information is not directly available in the Suricata TLS events, it is present in the log as one of the TLS JA3S parameters. JA3S is a technique that is used to fingerprint the TLS implementation of servers. By analyzing the first message from the server, a predefined list of parameters is concatenated to characterize the behavior of a server. This string and its hashed version is added to the TLS event to permit server fingerprinting. You will see that the second parameter of the JA3S string is indeed the Cipher ID. This is an integer, as TLS does not send strings over the wire. So the first step to getting a human readable result is to extract this field and the second step will be to use a mapping to convert it to a string. 

We can use Splunk's extraction capabilities to get the value of the Cipher ID in a distinct field.

***  event_type=tls |***

***    spath tls.ja3s.string output=ja3s_string |***

***    eval ja3s_elt=split(ja3s_string,",") |***

***    eval cipher_id=mvindex(ja3s_elt, 1)***

Information can be extracted from [the IANA website](https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml) to build the mapping from integer to string. We can then create and use a lookup table in Splunk to get the string translation. The mapping created from IANA information is useful to query for the usage of some specific TLS cipher suites but it gives no information about the security level of the cipher suites.

[The French National Cybersecurity Agency](https://www.ssi.gouv.fr/en/) (ANSSI) has published ‘[*Security Recommendations for TLS*](https://www.ssi.gouv.fr/guide/recommandations-de-securite-relatives-a-tls)”. In this document, they define a list of recommended TLS cipher suites. Their classification also contains ‘degraded’ TLS cipher suites that are ok to use if there are no viable alternatives. All other TLS cipher suites should be considered as insecure. The US [National Security Agenc](https://www.nsa.gov/)y (NSA) issued similar guidance in its recently-published CSI sheet, entitled "[Eliminating Obsolete Transport Layer Security (TLS) Protocol Configurations](https://media.defense.gov/2021/Jan/05/2002560140/-1/-1/0/ELIMINATING_OBSOLETE_TLS_UOO197443-20.PDF)"

By merging the information from IANA with the one from ANSSI, we obtain a mapping that links the cipher ID, their name, and their security level. This mapping is available in the [version 1.0.0 of the Stamus App for Splunk](https://splunkbase.splunk.com/app/5262).

With this mapping it is possible to search and do statistics on the security of the TLS cipher suite seen on the network. For example, to list all insecure TLS connections seen on the network, one can issue the following query in Splunk:

***  event_type=tls |***

***    spath tls.ja3s.string output=ja3s_string |***

***    eval ja3s_elt=split(ja3s_string,",") |***

***    eval cipher_id=mvindex(ja3s_elt, 1) |***

***    lookup tls_cipher_mapping.csv id as cipher_id |***

***    search cipher_security=insecure***

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXe8e0XximmmZC__iYPT-HEE0JF1z8ezZdwUtr9REq50qKeIhpUux9vcFFCb07mAUUzDHJPo4ORkuB9ezzaJaaXLfi4YTSQPy8Ta_j67WFw7HEnB-O1JoC7dg5WeyVm7u1mmQNYLUoo7sgEDNycToW6jlfIF?key=ydKSN5uwiMA9QBP589QvJVgX)

Using this technique, it is possible to build searches that classify the TLS cipher suites and

display the insecure ones. This is available in one of the Stamus Splunk App dashboards as shown on the illustration above. 

## Conclusion

The Stamus Networks App for Splunk enables threat hunters, incident responders, and other security practitioners who use Splunk to tap into the power of the Stamus Security Platform and Suricata to more effectively do their jobs. To learn more about the Stamus App for Splunk, [visit our page on Splunkbase](https://splunkbase.splunk.com/app/5262). 

 

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fanalysis-of-tls-cipher-suite-security-in-stamus-app-for-splunk%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Eric Leblond](https://www.stamus-networks.com/hubfs/Stamus_Eric_Square-1.jpg)

#### Eric Leblond

 Éric Leblond is the co-founder and chief technology officer (CTO) at Stamus Networks. He sits on the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities. He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is part of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is a respected expert and speaker on all things network security. Éric resides in Escalles, France.

[**](https://www.linkedin.com/in/ericleblond) [** ](https://twitter.com/Regiteric)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

### [Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.