首页> 外国专利> Detection of man-in-the-middle in HTTPS transactions independent of certificate trust chain

Detection of man-in-the-middle in HTTPS transactions independent of certificate trust chain

机译:独立于证书信任链的HTTPS事务中间人检测

摘要

Various methods for detecting a man-in-the-middle (MITM) during HTTPS communications are disclosed including, in some aspects, establishing a TCP connection for the retrieval of a web page from a domain name using an alternate IP address that is different from the IP address of the target domain where receipt of the target web page in response to a HTTP GET message indicates that a MITM is present, using a domain name as the SNI in a TLS connection and an alternate domain name in a HTTP GET message where receipt of a target web page of the alternate domain name indicates that a MITM is present, and generating an alternate domain name using a domain generation algorithm and using the generated alternate domain name as the SNI in the TLS message where receipt of a certificate for the generated alternate domain name indicates that a MITM is present.
机译:公开了用于在HTTPS通信期间检测中间人(MITM)的各种方法,包括在某些方面,建立TCP连接以使用不同于以下内容的备用IP地址从域名中检索网页:目标域的IP地址,在其中接收到响应HTTP GET消息的目标网页指示存在MITM,使用域名作为TLS连接中的SNI和HTTP GET消息中的备用域名,其中接收到备用域名的目标网页表示存在一个MITM,并使用域生成算法并使用生成的备用域名作为TLS消息中的SNI生成备用域名,其中生成的备用域名表示存在一个MITM。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号