摘要
文中在研究了目前广泛应用的HTTPS协议的基础上,分析了HTTPS会话劫持的手段和方法,并重点分析和揭示了一种基于中间人攻击(MITM)的HTTPS会话劫持方法—SSLStrip。进而提出了关于HTTPS协议本身以及所有通过HTTPS进行涉密交互的客户端的安全性问题,并提供了针对SSLStrip可行的防范措施。
This article analyzes the extensively-employed HTTPS protocol and discusses the common HTTPS hijacking methods and techniques. A specific practical way SSLStrip, which is based on man-in-the-middle technique(MITM), is proposed and analyzed in detail. The article exposes the obscure security problems concerned with https-based communication, which is generally believed to be quite safe, and provides some defending measures against SSLStrip attack.
出处
《信息安全与通信保密》
2009年第10期80-82,共3页
Information Security and Communications Privacy