We presented our analysis for SSL/TLS attacks. We found serious logic flaws in advanced attacks mechanisms. We discussed the weaknesses and ways of its protection.
SSL/TSL has been around for many years without any major modifications. This protocol was considered to be secure. The CRIME, BREACH,BEAST, Hartbleed attacks proved that in one very specific use case it can be compromised. While this use case can be avoided and SSL/TSL re-secured, will this have an effect on the thoughts of SSL/TSL security as a whole. People tend to lose faith in security protocols as soon as the simplest attack is successful. Will this be the end to SSL/TSL, or will users still have faith in the non-compressed version, that has yet to be broken, or will they run to a new protocol to be positive that they are secure? This will only be answered in time.
We believe that our study takes some steps in the security problem space that SSL protocols have brought. Also our study suggests and analyses Heartbleed exploit detection. We believe that our study brings some new chain of trust between the client and the protocol security. In future work we are considering the security challenges that come with other advanced SSL attacks. Fundamentally, we believe that vulnerabilities of SSL/TSL demands new research efforts on ensuring the security quality of the protocols
We presented our analysis for SSL/TLS attacks. We found serious logic flaws in advanced attacks mechanisms. We discussed the weaknesses and ways of its protection.
SSL/TSL has been around for many years without any major modifications. This protocol was considered to be secure. The CRIME, BREACH,BEAST, Hartbleed attacks proved that in one very specific use case it can be compromised. While this use case can be avoided and SSL/TSL re-secured, will this have an effect on the thoughts of SSL/TSL security as a whole. People tend to lose faith in security protocols as soon as the simplest attack is successful. Will this be the end to SSL/TSL, or will users still have faith in the non-compressed version, that has yet to be broken, or will they run to a new protocol to be positive that they are secure? This will only be answered in time.
We believe that our study takes some steps in the security problem space that SSL protocols have brought. Also our study suggests and analyses Heartbleed exploit detection. We believe that our study brings some new chain of trust between the client and the protocol security. In future work we are considering the security challenges that come with other advanced SSL attacks. Fundamentally, we believe that vulnerabilities of SSL/TSL demands new research efforts on ensuring the security quality of the protocols
การแปล กรุณารอสักครู่..
