首页> 外文会议>International Joint Conference on Computer Science and Software Engineering >Web Encryption Analysis of Internet Banking Websites in Thailand
【24h】

Web Encryption Analysis of Internet Banking Websites in Thailand

机译:泰国网上银行网站网加密分析

获取原文

摘要

With Thailand rapidly moving to a full internet banking ecosystem, the demand for online security has never been needed more than it is today. As the security and privacy of internet users depend on HTTPS, a web encryption protocol, for securing communication between users and web servers, HTTPS is essentially the center of the web ecosystem today. Unfortunately, despite the increasing number of HTTPS adoptions, numerous studies have shown that a large number of websites have adopted HTTPS incorrectly, rendering users vulnerable to information leakages e.g., eavesdropping and man-in-the-middle attacks. The correctness of HTTPS deployment is even far greater for internet banking services due to carrying user’s sensitive information and being prime targets for criminal activities.In this paper, we present WEAPONS, a novel black-box testing tool for evaluating the completeness and correctness of web encryption deployment including the deployment of HTTPS, and web encryption-related mechanisms i.e., HSTS, secure cookie, HTTPS redirect, HSTS preload. We use WEAPONS to conduct an assessment of 9 popular internet banking websites in Thailand during January – February 2020. We demonstrate that WEAPONS is able to find HTTPS deployment incorrectness. Several of these weaknesses can expose the affected services to man-in-the-middle attacks and sensitive data exposure.
机译:随着泰国迅速迁移到一个完整的网上银行生态系统,对在线安全的需求从未如此需要。由于互联网用户的安全性和隐私依赖于HTTPS,一种Web加密协议,用于保护用户和Web服务器之间的通信,HTTPS本质上是当今Web生态系统的中心。遗憾的是,尽管HTTPS采用越来越多,但许多研究表明,许多网站已经采用了不正确的HTTPS,使用户容易受到信息泄漏的影响,例如,窃听和中间人攻击。由于携带用户的敏感信息并作为犯罪活动的主要目标,HTTPS部署的正确性甚至更大。在本文中,我们提出了一种用于评估Web的完整性和正确性的新型黑匣子测试工具的武器加密部署包括部署HTTPS,以及Web加密相关机制,即HSTS,Secure Cookie,HTTPS重定向,HSTS预加载。我们使用武器在1月20日至2月在泰国进行评估。我们展示了武器能够找到HTTPS部署不正确。这些弱点中的几个可以将受影响的服务暴露于中间人攻击和敏感数据曝光。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号