• DocumentCode
    3765358
  • Title

    Classification of SSL Servers based on their SSL Handshake for Automated Security Assessment

  • Author

    Sirikarn Pukkawanna;Gregory Blanc;Joaquin Garcia-Alfaro;Youki Kadobayashi;Herve Debar

  • Author_Institution
    Nara Inst. of Sci. &
  • fYear
    2014
  • Firstpage
    30
  • Lastpage
    39
  • Abstract
    The Secure Socket Layer (SSL) and Transport Layer Security (TLS) are the most widely deployed security protocols used in systems required to secure information such as online banking. In this paper, we propose three handshake information-based methods for classifying SSL/TLS servers in terms of security: (1) Distinguished Names-based, (2) protocol version and encryption algorithm-based, and (3) combined vulnerability score-based methods. We also classified real-world SSL/TLS servers, active during July 2010 to May 2011, using the proposed methods. Finally, we propose 45 features, deemed relevant to security assessment, for future SSL/TLS data collection. The classification results showed that servers had bimodal distribution, with mostly good and bad levels of security. The results also showed that the majority of the SSL/TLS servers had seemingly risky certificates, and used both risky protocol versions and encryption algorithms.
  • Keywords
    "Servers","Protocols","Browsers","Encryption","Internet"
  • Publisher
    ieee
  • Conference_Titel
    Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS), 2014 Third International Workshop on
  • Print_ISBN
    978-1-4799-8308-7
  • Type

    conf

  • DOI
    10.1109/BADGERS.2014.10
  • Filename
    7446033