Measuring the Security Harm of TLS Crypto Shortcuts

Measuring the Security Harm of TLS Crypto Shortcuts
复制标题

衡量 TLS 加密快捷方式的安全危害

DOI:
--
复制
发表时间:
2016
期刊:
ACM/SIGCOMM Internet Measurement Conference
影响因子:
--
通讯作者:
J. A. Halderman
J. A. Halderman
中科院分区:
--
文献类型:
--
作者:
Drew Springall;Zakir Durumeric;J. A. Halderman

文献摘要

被引文献

相似文献

TLS有可能提供强大的保护,以抵御基于网络的攻击者和大规模监视,但许多实现都采取了安全捷径,以减少加密计算和网络往返的成本。我们报告了一项为期九周的研究结果,该研究测量了Alexa Top Million域中HTTPS网站的这些快捷方式的使用和安全影响。我们发现DHE和ECDHE私有值重用、TLS会话恢复和TLS会话票证的广泛部署。这些做法大大降低了前向保密提供的保护:如果服务器在24小时后被攻破,则到Top Million HTTPS站点的连接中有38%容易被解密,而10%在30天后,无论选择的密码套件如何。我们还调查了跨域共享TLS秘密和会话状态的做法,发现在某些情况下,窃取单个秘密值可能会危及与数万个站点的连接。这些结果表明,网站运营商需要更好地了解优化TLS性能和提供强大安全性之间的权衡,特别是在面对具有侵略性,大规模监视历史的民族国家攻击者时。
TLS has the potential to provide strong protection against network-based attackers and mass surveillance, but many implementations take security shortcuts in order to reduce the costs of cryptographic computations and network round trips. We report the results of a nine-week study that measures the use and security impact of these shortcuts for HTTPS sites among Alexa Top Million domains. We find widespread deployment of DHE and ECDHE private value reuse, TLS session resumption, and TLS session tickets. These practices greatly reduce the protection afforded by forward secrecy: connections to 38% of Top Million HTTPS sites are vulnerable to decryption if the server is compromised up to 24 hours later, and 10% up to 30 days later, regardless of the selected cipher suite. We also investigate the practice of TLS secrets and session state being shared across domains, finding that in some cases, the theft of a single secret value can compromise connections to tens of thousands of sites. These results suggest that site operators need to better understand the tradeoffs between optimizing TLS performance and providing strong security, particularly when faced with nation-state attackers with a history of aggressive, large-scale surveillance.