中文
相关论文

相关论文: DSTC: DNS-based Strict TLS Configurations

200 篇论文

The adoption of security protocols such as Transport Layer Security (TLS) has significantly improved the state of traffic encryption and integrity protection on the Internet. Despite rigorous analysis, vulnerabilities continue to emerge,…

密码学与安全 · 计算机科学 2025-01-30 Mariam Moustafa , Mohit Sethi , Tuomas Aura

The critical role that Network Time Protocol (NTP) plays in the Internet led to multiple efforts to secure it against time-shifting attacks. A recent proposal for enhancing the security of NTP with Chronos against on-path attackers seems…

密码学与安全 · 计算机科学 2020-10-19 Philipp Jeitner , Haya Shulman , Michael Waidner

The traditional design principle for Internet protocols indicates: "Be strict when sending and tolerant when receiving" [RFC1958], and DNS is no exception to this. The transparency of DNS in handling the DNS records, also standardised…

密码学与安全 · 计算机科学 2022-05-12 Philipp Jeitner , Haya Shulman

Active measurements can be used to collect server characteristics on a large scale. This kind of metadata can help discovering hidden relations and commonalities among server deployments offering new possibilities to cluster and classify…

网络与互联网体系结构 · 计算机科学 2023-08-31 Markus Sosnowski , Johannes Zirngibl , Patrick Sattler , Georg Carle , Claas Grohnfeldt , Michele Russo , Daniele Sgandurra

HTTPS is quickly rising alongside the need of Internet users to benefit from security and privacy when accessing the Web, and it becomes the predominant application protocol on the Internet. This migration towards a secure Web using HTTPS…

密码学与安全 · 计算机科学 2020-08-20 Wazen M. Shbair , Thibault Cholez , Jerome Francois , Isabelle Chrisment

The Domain Name System (DNS) is the foundation of a human-usable Internet, responding to client queries for host-names with corresponding IP addresses and records. Traditional DNS is also unencrypted, and leaks user information to network…

The Transport Layer Security (TLS) protocol is a de facto standard of secure client-server communication on the Internet. Its security can be diminished by a variety of attacks that leverage on weaknesses in its design and implementations.…

密码学与安全 · 计算机科学 2018-04-04 Pawel Szalachowski

Today, Internet offers many critical applications. So, it becomes very crucial for Internet service providers to ensure traceability of operations and to secure data exchange. Since all these communications are based on the use of the…

密码学与安全 · 计算机科学 2012-08-01 Kaouthar Chetioui , Ghizlane Orhanou , Said El Hajji , Abdelmajid Lakbabi

If two or more identical HTTPS clients, located at different geographic locations (regions), make an HTTPS request to the same domain (e.g. example.com), on the same day, will they receive the same HTTPS security guarantees in response? Our…

密码学与安全 · 计算机科学 2020-10-21 Eman Salem Alashwali , Pawel Szalachowski , Andrew Martin

The domain name system (DNS) that maps alphabetic names to numeric Internet Protocol (IP) addresses plays a foundational role for Internet communications. By default, DNS queries and responses are exchanged in unencrypted plaintext, and…

密码学与安全 · 计算机科学 2024-07-08 Minzhao Lyu , Hassan Habibi Gharakheili , Vijay Sivaraman

In the presence of security countermeasures, a malware designed for data exfiltration must do so using a covert channel to achieve its goal. Among existing covert channels stands the domain name system (DNS) protocol. Although the detection…

密码学与安全 · 计算机科学 2018-06-19 Asaf Nadler , Avi Aminov , Asaf Shabtai

Distribution Service (DDS) is a realtime peer-to-peer protocol that serves as a scalable middleware between distributed networked systems found in many Industrial IoT domains such as automotive, medical, energy, and defense. Since the…

密码学与安全 · 计算机科学 2019-08-16 Ruffin White , Gianluca Caiazza , Chenxu Jiang , Xinyue Ou , Zhiyue Yang , Agostino Cortesi , Henrik Christensen

Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching…

密码学与安全 · 计算机科学 2024-06-06 Elias Heftrig , Haya Schulmann , Niklas Vogel , Michael Waidner

Testing of network services represents one of the biggest challenges in cyber security. Because new vulnerabilities are detected on a regular basis, more research is needed. These faults have their roots in the software development cycle or…

密码学与安全 · 计算机科学 2018-03-29 Josip Bozic , Lina Marsso , Radu Mateescu , Franz Wotawa

Our objective is to protect the integrity and confidentiality of applications operating in untrusted environments. Trusted Execution Environments (TEEs) are not a panacea. Hardware TEEs fail to protect applications against Sybil, Fork and…

Many applications and protocols depend on the ability to generate a pool of servers to conduct majority-based consensus mechanisms and often this is done by doing plain DNS queries. A recent off-path attack [1] against NTP and security…

密码学与安全 · 计算机科学 2020-10-20 Philipp Jeitner , Haya Shulman , Michael Waidner

Distributed Denial of Service (DDoS) attacks exhaust victim's bandwidth or services. Traditional architecture of Internet is vulnerable to DDoS attacks and an ongoing cycle of attack & defense is observed. In this paper, different types and…

密码学与安全 · 计算机科学 2014-03-24 Muhammad Aamir , Mustafa Ali Zaidi

We use positional-unigram byte models along with maximum likelihood for generalized TLS fingerprinting and empirically show that it is robust to cipher stunting. Our approach creates a set of positional-unigram byte models from client hello…

密码学与安全 · 计算机科学 2024-05-14 Hector A. Valdez , Sean McPherson

The robustness principle, written by Jon Postel in an early version of TCP implementation, states that the communicating entities should be liberal while accepting the data. Several entities on the Internet do follow this principle. For…

密码学与安全 · 计算机科学 2022-04-01 Nikhil Tripathi

With the goal of improving the security of Internet protocols, we seek faster, semi-automatic methods to discover new vulnerabilities in protocols such as DNS, BGP, and others. To this end, we introduce the LLM-Assisted Protocol Attack…

密码学与安全 · 计算机科学 2025-10-23 R. Can Aygun , Yehuda Afek , Anat Bremler-Barr , Leonard Kleinrock