CryptoLens
TLS evidence collection, ML-assisted configuration risk scoring and actionable remediation.
2026Seven protocol, certificate and transport-security features.
TLS evidence to configuration risk
CryptoLens collects TLS/HTTP configuration evidence, encodes seven features and presents ML-assisted risk assessment with actionable remediation. Python scanning/extraction feeds scikit-learn classifiers; Streamlit provides scan and result views with SQLite/SQLAlchemy persistence.
Protocol/cipher support, certificate properties and HSTS information remain visible alongside the model score. The included evaluation uses demonstration data with synthetic augmentation.
Scan to investigation
- TLS probe
- Feature extraction
- Model inference
- Stored scan
- Remediation
A shared feature schema connects the scanner, training pipeline and application.
Seven configuration features
Scroll horizontally to compare.
| Feature | What it captures |
|---|---|
| TLS version | The negotiated protocol generation. |
| Cipher suite | The selected cryptographic suite. |
| Weak-cipher flag | Whether a configured weak-cipher condition is detected. |
| Forward secrecy | The handshake’s key-exchange characteristic. |
| Certificate key length | The size of the public key represented by the certificate. |
| Certificate expiry days | The remaining certificate lifetime. |
| HSTS support | Whether the HTTP strict-transport header is present. |
Model comparison
Recorded evaluation on the project’s included synthetic/augmented demonstration dataset. Gradient Boosting was selected by the training workflow.
Engineering decisions
Numerical and categorical encoding provides a consistent feature contract. Random Forest and Gradient Boosting compare decision boundaries over that representation; the included Random Forest has 300 trees. The extractor connects input attributes back to scanner evidence.
Remediation is rule-based guidance tied to weak configuration signals. Stored assessments support review and comparison. Risk scoring prioritizes attention, while protocol versions, certificate details and transport headers explain the configuration itself. Keeping model metadata, feature encoding and evidence separate makes the comparison understandable. The ROC AUC comparison uses the included synthetic/augmented dataset.