期刊文献+

SSL VPN的安全漏洞及其解决方案 被引量:11

The Threats in SSL VPN and the Solutions
下载PDF
导出
摘要 SSLVPN应用自问世以来便以其相对于传统的IPSECVPN技术的高易用性、良好的可扩展性、低管理和低部署成本等优势而逐渐受到各安全生产商和应用企业的青睐。但是,作为一种新的安全技术,SSLVPN自身又会带来诸多安全性的问题。本文旨在对浏览器/服务器模式的SSLVPN体系结构的安全问题进行分析,分别指出了浏览器端和服务器端存在的隐私数据遗留、非安全退出、应用层漏洞和身份认证等安全威胁,并针对这些问题给出了相应的解决方案。 SSL VPN Applications present an exciting new development trend m remote-access technology. As they require no client-side software other than a Web browser, SSL VPN offers great convenience, and promises to provide a much lower Total Cost of Ownership than the traditional IPSEC VPN. Yet, at the same time, this novel technology presents new challenges in the realm of security. This paper explores the security issues in the SSL VPN client/server model, explains the threats inherent both on the client side and on the server side, such as “sensitive data remaining on insecure access devices”, “insecure logout”, “application-level vulnerabilities”, “authentication”, and so on. Finally, we discuss the technologies to address them.
出处 《计算机工程与科学》 CSCD 2006年第8期9-10,13,共3页 Computer Engineering & Science
关键词 SSL VPN 体系结构 安全问题 SSL VPN architecture security
  • 相关文献

参考文献5

  • 1包丽红,李立亚.基于SSL的VPN技术研究[J].网络安全技术与应用,2004(5):38-40. 被引量:19
  • 2Andrew Harding . SSL Virtual Private Networks[J]. Computers and Security,2003,20(5) :416-420.
  • 3End-to-End Application Level Security [EB/OL]. http://www. networknewz. com/2004/1007.html, 2005-04.
  • 4T Dierks,C Allen. The TLS Protocol Version 1.0[R]. RFC 2246,1999.
  • 5Jose Nazario. Defense and Detection Strategies Against Worms[M]. London: Arteeh House, 2004.

共引文献18

同被引文献41

引证文献11

二级引证文献15

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部