Taxonomy of Man-in-the-Middle Attacks on HTTPS

被引:0
作者
Stricot-Tarboton, Shaun [1 ]
Chaisiri, Sivadon [1 ]
Ko, Ryan K. L. [1 ]
机构
[1] Univ Waikato, Cyber Secur Lab, Hamilton, New Zealand
来源
2016 IEEE TRUSTCOM/BIGDATASE/ISPA | 2016年
关键词
HTTPS; TLS; SSL; Man-in-the-Middle; taxonomy; communications security; classification framework; cyber security;
D O I
10.1109/TrustCom.2016.105
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increase in Man-in-the-Middle (MITM) attacks capable of breaking Hypertext Transfer Protocol Secure (HTTPS) over the past five years, researchers tasked with the improvement of HTTPS must understand each attacks characteristics. However with the large amount of attacks it is difficult to discern attack differences, with out any existing classification system capable of classifying these attacks. In this paper we provide a framework for classifying and mitigating MITM attacks on HTTPS communications. The identification and classification of these attacks can be used to provide useful insight into what can be done to improve the security of HTTPS communications. The classification framework was used to create a taxonomy of MITM attacks providing a visual representation of attack relationships, and was designed to flexibly allow other areas of attack analysis to be added. The classification framework was tested against a testbed of MITM attacks, then further validated and evaluated at the INTERPOL Global Complex for Innovation (IGCI) with a forensic taxonomy extension, and forensic analysis tool.
引用
收藏
页码:527 / 534
页数:8
相关论文
共 26 条
  • [1] [Anonymous], 2008, 5246 RFC
  • [2] Asokan N., 2003, Security Protocols. 11th International Workshop. Revised Selected Papers (Lecture Notes in Computer Science Vol. 3364), P28
  • [3] Cebula J.J., 2014, A taxonomy of operational cyber security risks version 2
  • [4] Cve. mitre. org, 2016, CVE COMM VUL EXP CVE
  • [5] Dierks T., 2006, 4246 RFC
  • [6] Dierks T., 1999, 2246 RFC, DOI 10.17487/RFC2246
  • [7] Franks J., 1999, HTTP AUTHENTICATION
  • [8] Freier Alan O., 2011, RFC 6101
  • [9] A taxonomy of networks and computer attacks
    Hansman, S
    Hunt, R
    [J]. COMPUTERS & SECURITY, 2005, 24 (01) : 31 - 43
  • [10] Holz R., 2015, 7525 RFC