首页> 外文会议>IEEE Symposium on Security and Privacy >Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
【24h】

Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem

机译:HTTP后世界的明信片:Web生态系统中HTTPS漏洞的放大

获取原文

摘要

HTTPS aims at securing communication over the Web by providing a cryptographic protection layer that ensures the confidentiality and integrity of communication and enables client/server authentication. However, HTTPS is based on the SSL/TLS protocol suites that have been shown to be vulnerable to various attacks in the years. This has required fixes and mitigations both in the servers and in the browsers, producing a complicated mixture of protocol versions and implementations in the wild, which makes it unclear which attacks are still effective on the modern Web and what is their import on web application security. In this paper, we present the first systematic quantitative evaluation of web application insecurity due to cryptographic vulnerabilities. We specify attack conditions against TLS using attack trees and we crawl the Alexa Top 10k to assess the import of these issues on page integrity, authentication credentials and web tracking. Our results show that the security of a consistent number of websites is severely harmed by cryptographic weaknesses that, in many cases, are due to external or related-domain hosts. This empirically, yet systematically demonstrates how a relatively limited number of exploitable HTTPS vulnerabilities are amplified by the complexity of the web ecosystem.
机译:HTTPS的目的是通过提供一个加密保护层来确保Web上的通信安全,该保护层可确保通信的机密性和完整性并启用客户端/服务器身份验证。但是,HTTPS基于SSL / TLS协议套件,这些套件已证明多年来容易受到各种攻击。这需要在服务器和浏览器中进行修复和缓解,从而在野外产生复杂的协议版本和实现的混合,这使得不清楚哪种攻击在现代Web上仍然有效,以及它们在Web应用程序安全性上的意义是什么。 。在本文中,我们提出了由于加密漏洞而对Web应用程序不安全性进行的第一个系统的定量评估。我们使用攻击树指定针对TLS的攻击条件,并且对Alexa Top 10k进行爬网,以评估这些问题在页面完整性,身份验证凭据和Web跟踪方面的重要性。我们的结果表明,在许多情况下,归因于外部或相关域主机的加密漏洞严重损害了一定数量网站的安全性。这从经验上却系统地证明了Web生态系统的复杂性如何放大了相对有限的可利用HTTPS漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号