PAS-2: HTTPS paths are only extracted if a TLS handshake has been observed

Project: PCAP Analysis Script (PAS)
At the moment, the script uses a list of domains seen in TLS handshakes to search HTTP referrers to identify paths visited on the HTTPS site.

If, however, the capture started after a TLS handshake, information on a given site will be missing despite the fact we have information readily available.

So, it may be better to look at extracting a list of HTTPS sites from the referrer headers that have been captured, and build the known SSL paths based on that information instead.

Currently undergoing a test run, but the script now extracts HTTPS FQDN's from the Referer's observed and then goes through to identify all traffic originating from that domain
That seems to have done the job quite nicely, also ran that section quite a lot quicker by the looks of it
Repo: PCAPAnalyseandReport
Commit: d7f666566324cc3539609643c69d9f4227512b3b
Date: Sun Nov 22 12:09:49 2015 +0000

Date: Sun Nov 22 12:09:49 2015 +0000
Commit Message: SSL path extraction now based on HTTP Referer. See PAS-2

