Title :
SSL/TLS attacks: Analysis and evaluation
Author :
Abeer E. W. Eldewahi;Tasneem M. H. Sharfi;Abdelhamid A. Mansor;Nashwa A. F. Mohamed;Samah M. H. Alwahbani
Author_Institution :
Faculty of Mathematical Sciences, University of Khartoum, Sudan
Abstract :
The Secure Socket Layer /Transport Layer Security (SSL/TLS) provides data confidentiality, integrity and authenticity between two communicating applications. There are many attacks appeared in different versions of SSL/TLS based on vulnerabilities related to the protocol structure and its implementation. This paper presents an analysis and evaluation of some theoretical and practical attacks on SSL/TLS, and divides them to two categories: attacks on Handshake protocol and attack on Record protocol. We evaluate each category based on specific criteria that selected to the current state of the art, such as: Weakness, which identifies the vulnerability of the system, Effect, which identifies the attacker harm the system, and Limitation, to identify the current countermeasures weaknesses.
Keywords :
"Protocols","Standards","Encryption","Switches"
Conference_Titel :
Computing, Control, Networking, Electronics and Embedded Systems Engineering (ICCNEEE), 2015 International Conference on
DOI :
10.1109/ICCNEEE.2015.7381362