首页> 外文OA文献 >Clubbing seals: Exploring the ecosystem of third-party security seals
【2h】

Clubbing seals: Exploring the ecosystem of third-party security seals

机译:俱乐部印章:探索第三方安全印章的生态系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In the current web of distrust, malware, and server compromises, convincing an online consumer that a website is secure, can make the difference between a visitor and a buyer. Third-party security seals position themselves as a solution to this problem, where a trusted external company vouches for the security of a website, and communicates it to visitors through a security seal which the certified website can embed in its pages.In this paper, we explore the ecosystem of third-party security seals focusing on their security claims, in an attempt to quantify the difference between the advertised guarantees of security seals, and reality. Through a series of automated and manual experiments, we discover a real lack of thoroughness from the side of the seal providers, which results in obviously insecure websites being certified as secure. Next to the incomplete protection, we demonstrate how malware can trivially evade detection by seal providers and detail a series of attacks that are actually facilitated by seal providers. Among other things, we show how seals can give more credence to phishing attacks, and how the current architecture of third-party security seals can be used as a completely passive vulnerability oracle, allowing attackers to focus their energy on websites with known vulnerabilities.
机译:在当前的不信任网络中,恶意软件和服务器受到威胁,使在线消费者确信网站是安全的,可以在访问者和购买者之间产生影响。第三方安全印章将自己定位为解决此问题的方法,在该解决方案中,受信任的外部公司担保网站的安全性,并通过安全印章将其传达给访问者,认证网站可将其嵌入到其页面中。我们将重点放在第三方安全印章上,探索第三方安全印章的生态系统,以试图量化所宣传的安全印章担保与现实之间的差异。通过一系列自动和手动实验,我们从印章提供者的角度发现了真正的不彻底,这导致明显不安全的网站被认证为安全。除了不完全的保护之外,我们还演示了恶意软件如何轻松地逃避密封提供者的检测,并详细介绍了密封提供者实际促进的一系列攻击。除其他外,我们展示了密封如何使网络钓鱼攻击更可信,以及如何将第三方安全密封的当前体系结构用作完全被动的漏洞预告片,从而使攻击者可以将精力集中在已知漏洞的网站上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号