首页> 外文期刊>Journal of computer security >Invalid certificates in modern browsers: A socio-technical analysis
【24h】

Invalid certificates in modern browsers: A socio-technical analysis

机译:现代浏览器中的无效证书:社会技术分析

获取原文
获取原文并翻译 | 示例
           

摘要

The authentication of a web server is a crucial procedure in the security of web browsing. It relies on certificate validation, a process that may require the participation of the user. Thus, the security of certificate validation is socio-technical as it depends on traditional security technology as well as on social elements such as cultural values, trust and human-computer interaction.This manuscript analyzes extensively the socio-technical security of certificate validation as carried out through today's most popular browsers. First, we model processes, protocols and ceremonies that browsers run with servers and users as UML activity diagrams. We consider both classic and private browsing modes and focus on the certificate validation. We then translate each UML activity diagram to a CSP# model. The model is expanded with the LTL formalization of five socio-technical properties pivoted on user involvement with certificate validation. We automatically check whether the CSP# models are socio-technically secure against Man-in-the-Middle attacks using the PAT model checker. The findings turn out to be far from straightforward. From them, we state best-practice recommendations to browser vendors.
机译:Web服务器的身份验证是Web浏览安全性中的关键过程。它依赖于证书验证,该过程可能需要用户的参与。因此,证书验证的安全性是社会技术的,因为它依赖于传统的安全技术以及诸如文化价值,信任和人机交互等社会元素。 r n此手稿对证书的社会技术安全性进行了广泛的分析。通过当今最流行的浏览器进行的验证。首先,我们将浏览器与服务器和用户一起运行的过程,协议和仪式建模为UML活动图。我们同时考虑经典浏览模式和私有浏览模式,并着重于证书验证。然后,我们将每个UML活动图转换为CSP#模型。 LTL形式化了五个社会技术属性,从而扩展了该模型,该属性以用户参与证书验证为中心。我们使用PAT模型检查器自动检查CSP#模型是否在社会技术上免受中间人攻击。结果发现远非如此简单。通过它们,我们向浏览器供应商提出最佳实践建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号