首页> 外文会议>Young Computer Scientists, ICYCS, 2008 9th International Conference for >Attacks vs. Countermeasures of SSL Protected Trust Model
【24h】

Attacks vs. Countermeasures of SSL Protected Trust Model

机译:SSL保护的信任模型的攻击与对策

获取原文

摘要

This paper analyzes the problems within current anti-spoofing mechanisms and proposes a new SSL protected trust model. Then, this paper describes the attacks on SSL protected trust model. This paper also proposes the new Automatic Detecting Security Indicator (ADSI) scheme to defend against spoofing attacks on SSL protected Web servers. This paper describes the ADSI-based trust model. In a secure transaction, ADSI may randomly generate a picture and embed it into the current Web browser. This can be triggered by any security relevant events occurred on the browser, and then performs automatic checking on current active security status. When a mismatch of embedded images is detected, an alarm goes off to alert the users. Since an adversary is hard to replace or mimic the randomly generated picture, the Web-spoofing attack can not be mounted easily. In comparison with existing proposals, the proposed scheme has the following advantages: (1) weak security assumption and very low burden on the customer by automating the process of detection and recognition of the Web-spoofing for SSL-enabled communications, (2) little intrusive on the browser, and (3) easy implementation in trusted PC at Internet Cafe requiring neither Logo Certification Authority, nor the scheme of personalization.
机译:本文分析了当前反欺骗机制中存在的问题,并提出了一种新的受SSL保护的信任模型。然后,本文描述了针对SSL保护的信任模型的攻击。本文还提出了一种新的自动检测安全指示器(ADSI)方案,以防御对受SSL保护的Web服务器的欺骗攻击。本文介绍了基于ADSI的信任模型。在安全交易中,ADSI可能会随机生成图片并将其嵌入到当前的Web浏览器中。这可以由浏览器上发生的任何与安全相关的事件触发,然后对当前活动的安全状态执行自动检查。当检测到嵌入图像不匹配时,警报响起,以警告用户。由于对手很难替换或模仿随机生成的图片,因此,网络欺骗攻击很难轻易发动。与现有的提议相比,该提议的方案具有以下优点:(1)通过自动化检测和识别启用SSL的通信的Web欺骗的过程,安全假设较弱且对客户的负担极低,(2)很少(3)在Internet Cafe的受信任PC上轻松实现,既不需要徽标证书颁发机构,也不需要个性化方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号