首页> 外文会议>Symposium on Chemistry as a second language >SSLock: Sustaining the Trust on Entities Brought by SSL
【24h】

SSLock: Sustaining the Trust on Entities Brought by SSL

机译:SSLOCK:维持SSL带来的实体的信任

获取原文

摘要

We propose a new, simple and effective domain segmentation approach to sustain SSL protection which is usually compromised when users are expected to perform legitimacy judgment. It has been established that using security warnings and indicators is a serious operational flaw of SSL. As a securitycritical system, SSL should never rely on users' judgment as the ultimate defense because adversaries that exploit users' ignorance and illiteracy are sufficient to break the most secure system. The proposal simply requires a service provider to opt-in by hosting its service in a special subdomain "secure". The enhanced protection will then be automatically in force. In this paper, we consider three severe and characteristic attack models, namely dynamic pharming, deceptive , captive portal and SSLStrip attacks, and we show that there is no single defeating solution except SSLock. We have conducted deployability analysis which further justifies the proposal in terms of its high compatibility rate. SSLock is the only approach that is generic and light-weight for application vendors, opt-in and zero initialization for service providers, and privacypreserving and idiot-proof for generic users.
机译:我们提出了一种新的,简单且有效的域分割方法,以维持SSL保护,这通常会受到影响,当用户预计执行合法性判断时。已经建立了使用安全警告和指标是SSL的严重运营缺陷。作为一种安全性系统,SSL永远不应依赖于用户的判断作为最终防范,因为利用用户无知和文盲的对手足以破坏最安全的系统。该提案只需通过在特殊子域“安全”中托管其服务来选择服务提供商。然后,增强的保护将自动生效。在本文中,我们考虑了三种严重和特色的攻击模型,即动态药物,欺骗性,俘虏门户和SSLSTRIP攻击,我们表明除了SSLock,没有单一的击败解决方案。我们进行了部署性分析,以便在高相容率方面进一步证明提案。 SSLock是唯一的方法,即服务提供商的应用供应商,选择和零初始化的通用和轻量级,以及通用用户的PrivacyPreserving和Idiot-id。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号