...
首页> 外文期刊>Security and communication networks >SSL-enabled trusted communication: Spoofing and protecting the non-cautious users
【24h】

SSL-enabled trusted communication: Spoofing and protecting the non-cautious users

机译:支持SSL的可信通信:欺骗和保护非谨慎用户

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The anti-spoofing community has been intensively proposing new methods for defending against new web-spoofing techniques. In this paper, we analyze the problems within current anti-spoofing mechanisms, and propose a new SSL protected trust model. Then, we describe the attacks on SSL protected trusted communication. In this paper, we also propose the new Automatic Detecting Security Indicator scheme (ADSI) to defend against spoofing attacks on SSL protected web servers. In a secure transaction, ADSI will randomly choose a picture and embed it into the current web browser at a random place. This can be triggered by any security relevant event that has occurred on the browser, and then automatic checking will be performed on the current active security status. When a mismatch of embedded pictures is detected, an alarm goes off to alert the users. Since an adversary is hard to replace or mimic the randomly embedded picture, the web-spoofing attack cannot be mounted easily. In comparison with existing schemes, (1) the proposed scheme has the weakest security assumption, and places a very low burden on the user by automating the process of detection and recognition of web-spoofing for SSL-enabled trusted communication; (2) it has little intrusiveness on the browser; and (3) it can be implemented in a trusted PC at an Internet Cafe. Copyright © 2009 John Wiley & Sons, Ltd.
机译:反欺骗社区一直在积极提出新的方法来防御新的网络欺骗技术。在本文中,我们分析了当前反欺骗机制中的问题,并提出了一种新的SSL保护的信任模型。然后,我们描述对SSL保护的受信任通信的攻击。在本文中,我们还提出了新的自动检测安全性指示器方案(ADSI),以防御受SSL保护的Web服务器上的欺骗攻击。在安全交易中,ADSI将随机选择图片并将其嵌入到当前Web浏览器中的任意位置。这可以由浏览器上发生的任何与安全相关的事件触发,然后将对当前的活动安全状态执行自动检查。当检测到嵌入图片不匹配时,警报响起,以警告用户。由于对手很难替换或模仿随机嵌入的图片,因此网络欺诈攻击很难轻易发动。与现有方案相比,(1)所提出的方案具有最弱的安全性假设,并且通过自动化检测和识别启用SSL的可信通信的网络欺骗的过程,给用户带来了非常低的负担; (2)对浏览器的干扰小; (3)可以在网吧的可信任PC中实现。版权所有©2009 John Wiley&Sons,Ltd.

著录项

  • 来源
    《Security and communication networks》 |2011年第4期|p.372-383|共12页
  • 作者单位

    School of Information Science and Engineering, Central South University, Changsha, 410083, PR. China;

    School of Information Science and Engineering, Central South University, Changsha, 410083, PR. China;

    School of Information Science and Engineering, Central South University, Changsha, 410083, PR. China,Department of Computer and Information Sciences, Temple University, Philadelphia, PA 19122, U.S.A;

    Department of Computer and Information Sciences, Temple University, Philadelphia, PA 19122, U.S.A;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    automatic detecting; security indicator; web-spoofing; secure socket layer; trusted communication;

    机译:自动检测;安全指标;网络欺骗;安全插座层;信任的沟通;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号