TLS Connection Validation by Web Browsers: Why do Web Browsers Still Not Agree?

TLS Connection Validation by Web Browsers: Why do Web Browsers Still Not Agree?
复制标题

Web 浏览器进行 TLS 连接验证:为什么 Web 浏览器仍然不同意?

DOI:
10.1109/compsac.2017.240
复制
发表时间:
2017
期刊:
2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
A. Benzekri
A. Benzekri
中科院分区:
--
文献类型:
--
作者:
A. Wazan;R. Laborde;D. Chadwick;F. Barrère;A. Benzekri

文献摘要

被引文献

相似文献

TLS协议是用于保护Web交易的主要技术。它基于X.509证书,用于将Web服务器所有者的身份绑定到其公钥。Web浏览器代表Web用户执行X.509证书的验证。我们之前在2009年的研究表明,Web浏览器的验证过程是不一致和有缺陷的。我们展示了这种情况如何对网络用户产生负面影响。从2009年到现在,许多新的X.509相关标准已经创建或更新。在本文中,我们在2009年的研究中进行了更多的实验,以突出Web浏览器行为的改进和/或回归。
The TLS protocol is the primary technology used for securing web transactions. It is based on X.509 certificates that are used for binding the identity of web servers' owners to their public keys. Web browsers perform the validation of X.509 certificates on behalf of web users. Our previous research in 2009 showed that the validation process of web browsers is inconsistent and flawed. We showed how this situation might have a negative impact on web users. From 2009 until now, many new X.509 related standards have been created or updated. In this paper, we performed an increased set of experiments over our 2009 study in order to highlight the improvements and/or regressions in web browsers' behaviours.