首页> 外文会议>2012 Fourth International Conference on Computational Intelligence, Communication Systems and Networks >Simple and Lightweight HTTPS Enforcement to Protect against SSL Striping Attack
【24h】

Simple and Lightweight HTTPS Enforcement to Protect against SSL Striping Attack

机译:简单轻量级的HTTPS实施以防御SSL条带化攻击

获取原文
获取原文并翻译 | 示例

摘要

SSL is a protocol for secured traffic connections. By using the SSL, HTTPS has been designed to prevent eavesdroppers and malicious users from web application services. However, man-in-the-middle attack techniques based on stripping and sniffing the HTTPS connections are still possible, causing security problems on web applications. Several scrip-kiddy tools to launch such attacks are easy to find and available on the Internet. In this paper, we therefore proposed a solution to protect against SSL striping attack. By enforcing a connection to HTTPS, our techniques determine the web URL and enforce the communication to HTTPS for protecting against the SSL striping attack. The experimental results on a test-bed have demonstrated an effectiveness and efficiency of our solution.
机译:SSL是用于安全通信连接的协议。通过使用SSL,HTTPS旨在防止窃听者和恶意用户访问Web应用程序服务。但是,仍然可以使用基于剥离和嗅探HTTPS连接的中间人攻击技术,从而在Web应用程序上引起安全问题。可以很容易地找到几种发动蠕虫攻击的工具,这些工具可以在Internet上找到。因此,在本文中,我们提出了一种防止SSL条带化攻击的解决方案。通过强制与HTTPS的连接,我们的技术可以确定Web URL并强制与HTTPS进行通信,以防止SSL条带化攻击。在测试床上的实验结果证明了我们解决方案的有效性和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号