HSTS Preloading is Ineffective as a Long-Term, Wide-Scale MITM-Prevention Solution: Results from Analyzing the 2013 - 2017 HSTS Preload List

HSTS Preloading is Ineffective as a Long-Term, Wide-Scale MITM-Prevention Solution: Results from Analyzing the 2013 - 2017 HSTS Preload List
复制标题

HSTS 预加载作为长期、大规模 MITM 预防解决方案是无效的:分析 2013 - 2017 HSTS 预加载列表的结果

DOI:
--
复制
发表时间:
2019
期刊:
arXiv.org
影响因子:
--
通讯作者:
Eunice Grace Gatdula
Eunice Grace Gatdula
中科院分区:
--
文献类型:
--
作者:
J. Roig;Eunice Grace Gatdula

文献摘要

被引文献

相似文献

HSTS(HTTP严格传输安全)通过允许Web服务器通知浏览器仅应使用安全的HTTPS连接来保护网站免受某些攻击。但是,这仍然使初始连接不安全,容易受到中间人攻击。大多数主流浏览器现在都支持HSTS预加载列表,它试图关闭这个初始漏洞。在这项研究中,研究人员分析了HSTS预加载列表,以了解截至2017年12月的部署和行业接受状况。这里的调查结果显示了一幅黯淡的画面:HSTS预加载列表的采用对于金融等基本行业来说似乎几乎为零,并且相当大比例的条目是测试站点或非功能性的。
HSTS (HTTP Strict Transport Security) serves to protect websites from certain attacks by allowing web servers to inform browsers that only secure HTTPS connections should be used. However, this still leaves the initial connection unsecured and vulnerable to man-in-the-middle attacks. The HSTS preload list, now supported by most major browsers, is an attempt to close this initial vulnerability. In this study, the researchers analyzed the HSTS preload list to see the status of its deployment and industry acceptance as of December 2017. The findings here show a bleak picture: adoption of the HSTS Preload List seem to be practically nil for essential industries like Finance, and a significant percentage of entries are test sites or nonfunctional.