Skip to main navigation Skip to search Skip to main content

Implementation Flaws in TLS Stacks: Lessons Learned and Study of TLS 1.3 Benefits

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In the years leading to the definition of TLS 1.3, many vulnerabilities have been published on the TLS protocol, including numerous implementation flaws affecting a wide range of independent stacks. The infamous Heartbleed bug, was estimated to affect more than 20% of the most popular HTTPS servers. We propose a structured review of these implementation flaws. By considering their consequences but also their root causes, we present some lessons learned or yet to be learned. We also assess the impact of TLS 1.3, the latest version of the protocol, on the security of SSL/TLS implementations.

Original languageEnglish
Title of host publicationRisks and Security of Internet and Systems - 15th International Conference, CRiSIS 2020, Revised Selected Papers
EditorsJoaquin Garcia-Alfaro, Jean Leneutre, Nora Cuppens, Reda Yaich
PublisherSpringer Science and Business Media Deutschland GmbH
Pages87-104
Number of pages18
ISBN (Print)9783030688868
DOIs
Publication statusPublished - 1 Jan 2021
Event15th International Conference on Risks and Security of Internet and Systems, CRISIS 2020 - Virtual, Online
Duration: 4 Nov 20206 Nov 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12528 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Conference on Risks and Security of Internet and Systems, CRISIS 2020
CityVirtual, Online
Period4/11/206/11/20

Fingerprint

Dive into the research topics of 'Implementation Flaws in TLS Stacks: Lessons Learned and Study of TLS 1.3 Benefits'. Together they form a unique fingerprint.

Cite this