Passer à la navigation principale Passer à la recherche Passer au contenu principal

TLS record protocol: Security analysis and defense-in-depth countermeasures for HTTPS

  • ANSSI
  • Sekoia

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

TLS and its main application HTTPS are an essential part of internet security. Since 2011, several attacks against the TLS Record protocol have been presented. To remediate these aws, countermeasures have been proposed. They were usually specific to a particular attack, and were sometimes in contradiction with one another. All the proofs of concept targeted HTTPS and relied on the repetition of some secret element inside the TLS tunnel. In the HTTPS context, such secrets are pervasive, be they authentication cookies or anti-CSRF tokens. We present a comprehensive state of the art of attacks on the Record protocol and the associated proposed countermeasures. In parallel to the community efforts to find reliable long term solutions, we propose masking mechanisms to avoid the repetition of sensitive elements, at the transport or application level. We also assess the feasibility and effciency of such defense-in-depth mechanisms. The recent POODLE vulnerability confirmed that our proposals could thwart unknown attacks, since they would have blocked it.

langue originaleAnglais
titreASIACCS 2015 - Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security
EditeurAssociation for Computing Machinery
Pages225-236
Nombre de pages12
ISBN (Electronique)9781450332453
Les DOIs
étatPublié - 14 avr. 2015
Evénement10th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2015 - Singapore, Singapour
Durée: 14 avr. 201517 avr. 2015

Série de publications

NomASIACCS 2015 - Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security

Une conférence

Une conférence10th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2015
Pays/TerritoireSingapour
La villeSingapore
période14/04/1517/04/15

Empreinte digitale

Examiner les sujets de recherche de « TLS record protocol: Security analysis and defense-in-depth countermeasures for HTTPS ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation