Speaking in tongues practical evaluation of TLS cipher suites compatibility

2015 12th International Joint Conference on e-Business and Telecommunications (ICETE)(2015)

引用 23|浏览5
暂无评分
摘要
The Transport Layer Security (TLS) protocol is still the de-facto standard for secure network connections over an insecure medium like the internet. But its flexibility concerning the algorithms used for securing a channel between two parties can also be a weakness, due to the possible agreement on insecure ciphers. In this work we examine an existing white paper (Applied Crypto Hardening) giving recommendations on how to securely configure SSL/TLS connections with regard to the practical feasibility of these recommendations. In addition we propose an additional configuration set with the aim of increasing compatibility as well as security. We also developed a small Cipher Negotiation Crawler (CiNeg) to test TLS-handshakes using given cipher configurations with a supplied list of websites and show its practical usability.
更多
查看译文
关键词
OpenSSL,O-Saft,Bettercrypto,Openssl-compare,Applied Crypto Hardening,Cipher Suite,Cipher String
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要