期刊文献+

基于SSLStrip的HTTPS会话劫持 被引量:9

HTTPS Session Hijacking Based on SSLStrip
原文传递
导出
摘要 文中在研究了目前广泛应用的HTTPS协议的基础上,分析了HTTPS会话劫持的手段和方法,并重点分析和揭示了一种基于中间人攻击(MITM)的HTTPS会话劫持方法—SSLStrip。进而提出了关于HTTPS协议本身以及所有通过HTTPS进行涉密交互的客户端的安全性问题,并提供了针对SSLStrip可行的防范措施。 This article analyzes the extensively-employed HTTPS protocol and discusses the common HTTPS hijacking methods and techniques. A specific practical way SSLStrip, which is based on man-in-the-middle technique(MITM), is proposed and analyzed in detail. The article exposes the obscure security problems concerned with https-based communication, which is generally believed to be quite safe, and provides some defending measures against SSLStrip attack.
出处 《信息安全与通信保密》 2009年第10期80-82,共3页 Information Security and Communications Privacy
关键词 SSLStrip HTTPS 信息安全 中间人攻击 SSLStrip HTTPS information security MITM
  • 相关文献

参考文献7

二级参考文献12

  • 1熊艳,覃俊.SSL协议及其几个安全性问题[J].中南民族大学学报(自然科学版),2005,24(3):85-88. 被引量:7
  • 2白志中,罗贇骞,夏靖波,赵锡溱,张瑞武.基于SSL协议的嵌入式WEB系统安全性研究与实现[J].电光与控制,2006,13(3):60-64. 被引量:4
  • 3Rich Larsen. An Overview of the SSL Protocol and Application to Virtual Private Networks[C]. SANS GIAC/ GSEC Practical Version 1.4b, September 29, 2003.
  • 4Stallings W. Cryptography and Network Security: Principles and Practice[M]. Prentice Hall, 1998.
  • 5Andrew Harding. SSL Virtual Private Networks [J]. Computers and Security, 2003, 20 (5): 416-420.
  • 6Andrew S.Tanenbaum.计算机网络[M].第4版,清华大学出版社,2004.
  • 7[1]Eric Rescorla.SSL and TLS,Addison-Wesley Professional.2000.10.
  • 8[2]Michael E.Principles of Information Security.2003.7.
  • 9Eric Rescorla.SSL and TLS.Designing and Building Secure Systems,2001.
  • 10CCITT.Recommendation X.509.The Directory-Authentication Framework.1988.

共引文献18

同被引文献17

引证文献9

二级引证文献43

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部