中文
相关论文

相关论文: An Empirical Analysis of HTTPS Configuration Secur…

200 篇论文

Internet browsers use security protocols to protect sensitive messages. An inductive analysis of TLS (a descendant of SSL 3.0) has been performed using the theorem prover Isabelle. Proofs are based on higher-order logic and make no…

密码学与安全 · 计算机科学 2019-07-18 Lawrence C. Paulson

Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguration vulnerabilities in the light of Spring security, which is…

密码学与安全 · 计算机科学 2020-07-29 Mazharul Islam , Sazzadur Rahaman , Na Meng , Behnaz Hassanshahi , Padmanabhan Krishnan , Danfeng , Yao

Electronic banking portals often sit in front of enterprise resource planning (ERP) systems such as SAP, mediating payment requests between users and back end financial infrastructure. When these integrations place excessive trust in client…

密码学与安全 · 计算机科学 2026-03-17 Vick Dini

Authenticating websites is an ongoing problem for users. Recent proposals have suggested strengthening current server authentication methods by incorporating website location as a comprehensible additional trust factor. In this work, we…

密码学与安全 · 计算机科学 2018-03-02 Der-Yeuan Yu , Elizabeth Stobert , David Basin , Srdjan Capkun

The DNS HTTPS resource record is a new DNS record type designed for the delivery of configuration information and parameters required to initiate connections to HTTPS network services. In addition, it is a key enabler for TLS Encrypted…

网络与互联网体系结构 · 计算机科学 2024-09-13 Hongying Dong , Yizhe Zhang , Hyeonmin Lee , Shumon Huque , Yixin Sun

The ongoing trend to move industrial appliances from previously isolated networks to the Internet requires fundamental changes in security to uphold secure and safe operation. Consequently, to ensure end-to-end secure communication and…

密码学与安全 · 计算机科学 2022-06-02 Markus Dahlmanns , Johannes Lohmöller , Jan Pennekamp , Jörn Bodenhausen , Klaus Wehrle , Martin Henze

Web content delivery is one of the most important services on the Internet. Access to websites is typically secured via TLS. However, this security model does not account for prefix hijacking on the network layer, which may lead to traffic…

网络与互联网体系结构 · 计算机科学 2015-11-03 Matthias Wählisch , Robert Schmidt , Thomas C. Schmidt , Olaf Maennel , Steve Uhlig , Gareth Tyson

Modern software systems are often highly configurable to tailor varied requirements from diverse stakeholders. Understanding the mapping between configurations and the desired performance attributes plays a fundamental role in advancing the…

软件工程 · 计算机科学 2024-02-12 Mingyu Huang , Peili Mao , Ke Li

In network management, when it comes to security breaches, human error constitutes a dominant factor. We present our tool topoS which automatically synthesizes low-level network configurations from high-level security goals. The automation…

网络与互联网体系结构 · 计算机科学 2016-04-04 Cornelius Diekmann , Andreas Korsten , Georg Carle

The first quantitative evaluation of the quality of corporate firewall configurations appeared in 2004, based on Check Point FireWall-1 rule-sets. In general that survey indicated that corporate firewalls were often enforcing poorly written…

密码学与安全 · 计算机科学 2009-11-09 Avishai Wool

Securing the communication between a web server and a browser is a fundamental task of securing the World Wide Web. Websites today rely heavily on HTTPS to set up secure connections. In recent years, several incidents undermined this trust…

密码学与安全 · 计算机科学 2021-05-13 Thomas Sutter , Kevin Lapagna , Peter Berlich , Marc Rennhard , Fabio Germann

Due to increasing digitalization, formerly isolated industrial networks, e.g., for factory and process automation, move closer and closer to the Internet, mandating secure communication. However, securely setting up OPC UA, the prime…

密码学与安全 · 计算机科学 2020-10-27 Markus Dahlmanns , Johannes Lohmöller , Ina Berenice Fink , Jan Pennekamp , Klaus Wehrle , Martin Henze

The security of the Internet rests on a small number of open-source cryptographic libraries: a vulnerability in any one of them threatens to compromise a significant percentage of web traffic. Despite this potential for security impact, the…

密码学与安全 · 计算机科学 2021-07-13 Jenny Blessing , Michael A. Specter , Daniel J. Weitzner

TLS protocol is an essential part of secure Internet communication. In past, many attacks have been identified on the protocol. Most of these attacks are due to flaws in protocol implementation. The flaws are due to improper design and…

网络与互联网体系结构 · 计算机科学 2019-02-21 Tarun Yadav , Koustav Sadhukhan

Smart local energy system (SLES) is considered as a promising pathway facilitating a more effective and localised operation, benefited from the complex information and communication technology (ICT) infrastructures and Internet of things…

密码学与安全 · 计算机科学 2021-08-19 Siyuan Dong , Jun Cao , Zhong Fan

Testing of network services represents one of the biggest challenges in cyber security. Because new vulnerabilities are detected on a regular basis, more research is needed. These faults have their roots in the software development cycle or…

密码学与安全 · 计算机科学 2018-03-29 Josip Bozic , Lina Marsso , Radu Mateescu , Franz Wotawa

Today, Internet becomes the essential part of our lives. Over 90 percent of the ecommerce is developed on the Internet. A security algorithm became very necessary for producer client transactions assurance and the financial applications…

密码学与安全 · 计算机科学 2009-07-30 R. K. Pateriya , J. L. Rana , S. C. Shrivastava , Jaideep Patel

In security engineering, including software security engineering, there is a well-known design paradigm telling to prefer safe and secure defaults. The paper presents a systematization of knowledge (SoK) of this paradigm by the means of a…

密码学与安全 · 计算机科学 2025-02-27 Jukka Ruohonen

This paper reports the results of a survey of 1,976 individuals regarding their opinions on TLS inspection, a controversial technique that can be used for both benevolent and malicious purposes. Responses indicate that participants hold…

密码学与安全 · 计算机科学 2016-06-13 Scott Ruoti , Mark O'Neil , Daniel Zappala , Kent Seamons

Web-fraud is one of the most unpleasant features of today's Internet. Two well-known examples of fraudulent activities on the web are phishing and typosquatting. Their effects range from relatively benign (such as unwanted ads) to downright…

密码学与安全 · 计算机科学 2015-03-13 Mishari Al Mishari , Emiliano De Cristofaro , Karim El Defrawy , Gene Tsudik