TLS record protocol: Security analysis and defense-in-depth countermeasures for HTTPS

Olivier Levillain, Baptiste Gourdin, Hervé Debar

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

TLS and its main application HTTPS are an essential part of internet security. Since 2011, several attacks against the TLS Record protocol have been presented. To remediate these aws, countermeasures have been proposed. They were usually specific to a particular attack, and were sometimes in contradiction with one another. All the proofs of concept targeted HTTPS and relied on the repetition of some secret element inside the TLS tunnel. In the HTTPS context, such secrets are pervasive, be they authentication cookies or anti-CSRF tokens. We present a comprehensive state of the art of attacks on the Record protocol and the associated proposed countermeasures. In parallel to the community efforts to find reliable long term solutions, we propose masking mechanisms to avoid the repetition of sensitive elements, at the transport or application level. We also assess the feasibility and effciency of such defense-in-depth mechanisms. The recent POODLE vulnerability confirmed that our proposals could thwart unknown attacks, since they would have blocked it.

Original languageEnglish
Title of host publicationASIACCS 2015 - Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages225-236
Number of pages12
ISBN (Electronic)9781450332453
DOIs
Publication statusPublished - 14 Apr 2015
Event10th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2015 - Singapore, Singapore
Duration: 14 Apr 201517 Apr 2015

Publication series

NameASIACCS 2015 - Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security

Conference

Conference10th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2015
Country/TerritorySingapore
CitySingapore
Period14/04/1517/04/15

Fingerprint

Dive into the research topics of 'TLS record protocol: Security analysis and defense-in-depth countermeasures for HTTPS'. Together they form a unique fingerprint.

Cite this