详细信息
HTTPAS: active authentication against HTTPS man-in-the-middle attacks ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:HTTPAS: active authentication against HTTPS man-in-the-middle attacks
作者:Zhou, Peng[1];Gu, Xiaojing[2]
机构:[1]Shanghai Univ, Sch Mech Engn & Automat, Shanghai, Peoples R China;[2]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai, Peoples R China
年份:2016
卷号:10
期号:17
起止页码:2308
外文期刊名:IET COMMUNICATIONS
收录:;EI(收录号:20164803056809);WOS:【SCI-EXPANDED(收录号:WOS:000388498700007)】;
基金:This work was partially supported by the National Natural Science Foundation of China (Nos. 61502293, 61633016 and 61673255), the Shanghai Young Eastern Scholar Program, the Young Teachers' Training Program for Shanghai College & University, and the Shanghai Key Laboratory of Power Station Automation Technology.
语种:英文
外文关键词:transport protocols; hypermedia; cryptographic protocols; Internet; HTTPAS; active authentication architecture; HTTPS man-in-the-middle attacks; hypertext transfer protocol secure; pre-trusted certificate authorities; CAs; notary-based systems; pre-shared secrets; openSSL suite; Internet path diversity
摘要:Hypertext transfer protocol secure (HTTPS) relies on a group of pre-trusted certificate authorities (CAs) for authentication and hence can avoid man-in-the-middle attacks. However unfortunately, this authentication architecture can be completely subverted in case any one (usually the weakest one) of CAs has been compromised. To tackle this critical flaw, pioneer works such as notary-based systems and pre-shared secrets have been proposed. These state-of-the-art techniques can neither seek maximal protection from available CAs nor resist potential man-in-the-middle variants. In this study, the authors propose HTTPAS, a new HTTP Active Secure framework that can enhance the HTTPS authentication against man-in-the-middle attacks by actively utilising available CAs and exploiting Internet path diversity as much as possible. In particular, HTTPAS is designed with four practical solutions, each of which can make a unique trade-off among authentication capability, deployment difficulty and efficiency. They have implemented HTTPAS using the open secure sockets layer (SSL) suite, and also evaluated the implementation through experiments on several public certificate data sets and the Internet. Their results have successfully confirmed the authentication effectiveness of HTTPAS with only a few performance overheads and moderate deployment effort.
参考文献:
正在载入数据...
