【24h】

Turning Active TLS Scanning to Eleven

机译:将活跃的TLS扫描到11

获取原文

摘要

Transport Layer Security (TLS) is the fundament of today's web security, but the majority of deployments are misconfigured and left vulnerable to a phletora of attacks. This negatively affects the overall healthiness of the TLS ecosystem, and as such all the protocols that build on top of it. Scanning a larger number of hosts or protocols such as the numerous IPv4-wide scans published recently for a list of known attacks in TLS is non-trivial. This is due to the design of the TLS handshake, where the server chooses the specific cipher suite to be used. Current scanning approaches have to establish an unnecessary large number of connections and amount of traffic. In this paper we present and implemented different optimized strategies for TLS cipher suite scanning that, compared to the current best practice, perform up to 3.2 times faster and with 94% less connections used while being able to do exhaustive scanning for many vulnerabilities at once. We thoroughly evaluated the algorithms using practical scans and an additional simulation for evaluating current cipher suite practices at scale. With this work full TLS cipher suite scans are brought to a new level, making them a practical tool for further empiric research.
机译:传输层安全性(TLS)是当今Web安全的基础,但大多数部署都是错误的配置,并且易受攻击的攻击攻击。这对TLS生态系统的整体健康产生了负面影响,以及建立在其顶部的所有协议。扫描更大数量的主机或协议,例如最近发布的众多IPv4范围扫描,以获得TLS中已知攻击列表的列表是非微不足道的。这是由于TLS握手的设计,服务器选择要使用的特定密码套件。当前的扫描方法必须建立不必要的大量连接和流量。在本文中,我们为TLS密码套件扫描提供了不同的优化策略,与当前的最佳实践相比,执行高达3.2倍,并且在能够一次性扫描许多漏洞的情况下使用94%的连接。我们使用实际扫描彻底评估了算法,以及用于在比例下评估当前密码套件实践的额外仿真。通过这项工作,全部TLS密码套件扫描被带到了一个新的水平,使其成为进一步验证研究的实用工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号