certificates
play

Certificates CS 142 Lecture Notes: Network Security Slide 1 - PowerPoint PPT Presentation

Certificates CS 142 Lecture Notes: Network Security Slide 1 SSL/TLS Overview Browser Server client-hello server-hello + {server-cert}SK CA Key exchange (several options) Random client-key-exchange: {K}PK server key K K {HTTP data}K Most


  1. Certificates CS 142 Lecture Notes: Network Security Slide 1

  2. SSL/TLS Overview Browser Server client-hello server-hello + {server-cert}SK CA Key exchange (several options) Random client-key-exchange: {K}PK server key K K {HTTP data}K Most common: only the server is authenticated CS 142 Lecture Notes: Network Security Slide 2

  3. SSL Stripping Replace https:// with http:// Active Attacker HTTP request HTTP request Modified response HTTP response HTTP request HTTPS request HTTP response HTTPS response Browser Server Attacker opens HTTPS Attacker observes session, forwards requests private info and responses CS 142 Lecture Notes: Network Security Slide 3

  4. HTTPS Indicators HTTP HTTPS Firefox 10 IE 8 Chrome 17 CS 142 Lecture Notes: Network Security Slide 4

  5. Mixed Content Indicators Silly dialogs Firefox 10: no SSL indicator Chrome 17: caution sign IE 8: warning dialog, no SSL lock CS 142 Lecture Notes: Network Security Slide 5

  6. CS 142 Lecture Notes: Network Security Slide 6

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend