...
【24h】

Taxonomy of SSL/TLS Attacks

机译:SSL / TLS攻击分类

获取原文
           

摘要

Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols use cryptographic algorithms to secure data and ensure security goals such as Data Confidentiality and Integrity in networking. They are used along with other protocols such as HTTP, SMTP, etc. in applications such as web browsing, electronic mail, and VoIP. The existing versions of the protocols as well as the cryptographic algorithms they use have vulnerabilities and is not resistant towards Man-In-The- Middle (MITM) attacks. Exploiting these vulnerabilities, several attacks have been launched on SSL/TLS such as session hijacking, version degradation, heart bleed, Berserk etc. This paper is a comprehensive analysis of the vulnerabilities in the protocol, attacks launched by exploiting the vulnerabilities and techniques to mitigate the flaws in protocols. A novel taxonomy of the attacks against SSL/TLS has been proposed in this paper.
机译:安全套接字层(SSL)和传输层安全性(TLS)协议使用加密算法来保护数据并确保安全目标,例如网络中的数据机密性和完整性。它们与其他协议(例如HTTP,SMTP等)一起在Web浏览,电子邮件和VoIP等应用程序中使用。协议的现有版本以及所使用的加密算法都存在漏洞,并且无法抵抗中间人(MITM)攻击。利用这些漏洞,已经对SSL / TLS发起了几种攻击,例如会话劫持,版本降级,心脏出血,Berserk等。本文对协议中的漏洞进行了全面分析,通过利用这些漏洞和技术来缓解攻击协议中的缺陷。本文提出了一种针对SSL / TLS攻击的新颖分类法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号