DocumentCode :
3289626
Title :
SSL/TLS Status Survey in Japan - Transitioning against the Renegotiation Vulnerability and Short RSA Key Length Problem
Author :
Suga, Yuji
Author_Institution :
Internet Initiative Japan Inc., Tokyo, Japan
fYear :
2012
fDate :
9-10 Aug. 2012
Firstpage :
17
Lastpage :
24
Abstract :
In 2009, researchers released details of a vulnerability in the SSL and TLS protocols that could allow Man-in-the-Middle attacks to be carried out. SSL and TLS operate between the IP and application layers and ensure application data encryption and data integrity, authenticating the target of communications using X.509 public key certificates. As they are used together with application layer communication protocols such as HTTP, SMTP, and POP, it seems that this vulnerability affects a large number of applications and systems. This vulnerability can be attributed to a problem in the SSL and TLS protocol specifications themselves. Fixes have been released for Open SSL and Apache immediately, however most of these involve simply disabling the renegotiation feature that is causing the problem. More thorough measures would require an update to the current specifications and migration to implementations that follow the new specifications. IETF published countermeasures with unprecedented speed as RFC5746, however server-side implementations are not deployed because of problems in business such as the loss of opportunities and backward compatibilities. This paper discusses about problems of a transitioning to new specifications including the SSL/TLS renegotiation vulnerability and short key lengths of RSA algorithm using in SSL/TLS, and also reports the latest status of these weakness on web sites of local governments and universities in Japan. Note that 40.7% local government are vulnerable against the DOS attack using the SSL/TLS renegotiation vulnerability and 36.9% sites use 1024 bit or less RSA keys.
Keywords :
IP networks; Web sites; computer network security; cryptographic protocols; data integrity; educational institutions; local government; public key cryptography; Apache; DOS attacks; IP layers; Japanese universities; OpenSSL; RSA keys; SSL protocol specifications; SSL/TLS Status Survey; TLS protocol specifications; X.509 public key certificates; application layer communication protocols; data encryption; data integrity; local governments; man-in-the-middle attacks; renegotiation vulnerability; short RSA key length problem; Encryption; Local government; Portals; Protocols; Public key; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security (Asia JCIS), 2012 Seventh Asia Joint Conference on
Conference_Location :
Tokyo
Print_ISBN :
978-1-4673-2261-4
Electronic_ISBN :
978-0-7695-4776-3
Type :
conf
DOI :
10.1109/AsiaJCIS.2012.10
Filename :
6298128
Link To Document :
بازگشت