首页> 外文会议>IEEE Symposium on Security and Privacy >Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
【24h】

Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem

机译:从后的HTTP世界的明信片:在Web生态系统中放大HTTPS漏洞

获取原文

摘要

HTTPS aims at securing communication over the Web by providing a cryptographic protection layer that ensures the confidentiality and integrity of communication and enables client/server authentication. However, HTTPS is based on the SSL/TLS protocol suites that have been shown to be vulnerable to various attacks in the years. This has required fixes and mitigations both in the servers and in the browsers, producing a complicated mixture of protocol versions and implementations in the wild, which makes it unclear which attacks are still effective on the modern Web and what is their import on web application security. In this paper, we present the first systematic quantitative evaluation of web application insecurity due to cryptographic vulnerabilities. We specify attack conditions against TLS using attack trees and we crawl the Alexa Top 10k to assess the import of these issues on page integrity, authentication credentials and web tracking. Our results show that the security of a consistent number of websites is severely harmed by cryptographic weaknesses that, in many cases, are due to external or related-domain hosts. This empirically, yet systematically demonstrates how a relatively limited number of exploitable HTTPS vulnerabilities are amplified by the complexity of the web ecosystem.
机译:HTTPS旨在通过提供保密保护层来确保网络通信,以确保通信的机密性和完整性并启用客户端/服务器身份验证。但是,HTTPS基于SSL / TLS协议套件,这些套件已被证明易受多年各种攻击的攻击。这在服务器和浏览器中都需要修复和缓解,从而在野外的协议版本和实现中产生复杂的混合,这使得它不清楚哪些攻击在现代Web上仍然有效,以及他们对Web应用程序安全的进口仍然是什么。在本文中,我们提出了由于加密漏洞引起的网络应用不安全的第一个系统定量评估。我们使用攻击树对TLS指定攻击条件,我们抓取Alexa Top 10k以评估页面完整性,身份验证凭据和Web跟踪上的这些问题的导入。我们的研究结果表明,一致数量的网站的安全性受到加密弱点的严重损害,在许多情况下,归因于外部或相关域主机。本验,但系统地展示了如何通过网络生态系统的复杂性放大了相对有限数量的可利用HTTPS漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号