Matches in SemOpenAlex for { <https://semopenalex.org/work/W2890128393> ?p ?o ?g. }
Showing items 1 to 87 of
87
with 100 items per page.
- W2890128393 abstract "Network traffic inspection, including TLS traffic, in enterprise environments is widely practiced. Reasons for doing so are primarily related to improving enterprise security (e.g., malware detection) and meeting legal requirements. To analyze TLS-encrypted data, network appliances implement a Man-in-the-Middle TLS proxy, by acting as the intended web server to a requesting client (e.g., a browser), and acting as the client to the outside web server. As such, the TLS proxy must implement both a TLS client and a server, and handle a large amount of traffic, preferably, in real-time. However, as protocol and implementation layer vulnerabilities in TLS/HTTPS are quite frequent, these proxies must be, at least, as secure as a modern, up-to-date web browser, and a properly configured web server. As opposed to client-end TLS proxies (e.g., as in several anti-virus products), the proxies in network appliances may serve hundreds to thousands of clients, and any vulnerability in their TLS implementations can significantly downgrade enterprise security. To analyze TLS security of network appliances, we develop a comprehensive framework, by combining and extending tests from existing work on client-end and network-based interception studies. We analyze thirteen representative network appliances over a period of more than a year (including versions before and after notifying affected vendors, a total of 17 versions), and uncover several security issues. For instance, we found that four appliances perform no certificate validation at all, three use pre-generated certificates, and eleven accept certificates signed using MD5, exposing their clients to MITM attacks. Our goal is to highlight the risks introduced by widely-used TLS proxies in enterprise and government environments, potentially affecting many systems hosting security, privacy, and financially sensitive data." @default.
- W2890128393 created "2018-09-27" @default.
- W2890128393 creator A5055898168 @default.
- W2890128393 creator A5082348165 @default.
- W2890128393 creator A5085765243 @default.
- W2890128393 date "2018-09-24" @default.
- W2890128393 modified "2023-09-27" @default.
- W2890128393 title "The Sorry State of TLS Security in Enterprise Interception Appliances." @default.
- W2890128393 cites W1439967542 @default.
- W2890128393 cites W1495444061 @default.
- W2890128393 cites W1708992266 @default.
- W2890128393 cites W1969343610 @default.
- W2890128393 cites W2103239853 @default.
- W2890128393 cites W2247093032 @default.
- W2890128393 cites W2536707834 @default.
- W2890128393 cites W2612070316 @default.
- W2890128393 cites W2612544399 @default.
- W2890128393 cites W2621197184 @default.
- W2890128393 cites W2650293344 @default.
- W2890128393 cites W2805984568 @default.
- W2890128393 cites W2307188943 @default.
- W2890128393 hasPublicationYear "2018" @default.
- W2890128393 type Work @default.
- W2890128393 sameAs 2890128393 @default.
- W2890128393 citedByCount "3" @default.
- W2890128393 countsByYear W28901283932019 @default.
- W2890128393 countsByYear W28901283932020 @default.
- W2890128393 countsByYear W28901283932021 @default.
- W2890128393 crossrefType "posted-content" @default.
- W2890128393 hasAuthorship W2890128393A5055898168 @default.
- W2890128393 hasAuthorship W2890128393A5082348165 @default.
- W2890128393 hasAuthorship W2890128393A5085765243 @default.
- W2890128393 hasConcept C136764020 @default.
- W2890128393 hasConcept C148176105 @default.
- W2890128393 hasConcept C148730421 @default.
- W2890128393 hasConcept C182590292 @default.
- W2890128393 hasConcept C196491621 @default.
- W2890128393 hasConcept C2779628075 @default.
- W2890128393 hasConcept C31258907 @default.
- W2890128393 hasConcept C35578498 @default.
- W2890128393 hasConcept C38652104 @default.
- W2890128393 hasConcept C41008148 @default.
- W2890128393 hasConcept C541664917 @default.
- W2890128393 hasConcept C59241245 @default.
- W2890128393 hasConcept C77088390 @default.
- W2890128393 hasConcept C79373723 @default.
- W2890128393 hasConceptScore W2890128393C136764020 @default.
- W2890128393 hasConceptScore W2890128393C148176105 @default.
- W2890128393 hasConceptScore W2890128393C148730421 @default.
- W2890128393 hasConceptScore W2890128393C182590292 @default.
- W2890128393 hasConceptScore W2890128393C196491621 @default.
- W2890128393 hasConceptScore W2890128393C2779628075 @default.
- W2890128393 hasConceptScore W2890128393C31258907 @default.
- W2890128393 hasConceptScore W2890128393C35578498 @default.
- W2890128393 hasConceptScore W2890128393C38652104 @default.
- W2890128393 hasConceptScore W2890128393C41008148 @default.
- W2890128393 hasConceptScore W2890128393C541664917 @default.
- W2890128393 hasConceptScore W2890128393C59241245 @default.
- W2890128393 hasConceptScore W2890128393C77088390 @default.
- W2890128393 hasConceptScore W2890128393C79373723 @default.
- W2890128393 hasLocation W28901283931 @default.
- W2890128393 hasOpenAccess W2890128393 @default.
- W2890128393 hasPrimaryLocation W28901283931 @default.
- W2890128393 hasRelatedWork W1497641109 @default.
- W2890128393 hasRelatedWork W2041950790 @default.
- W2890128393 hasRelatedWork W2053123811 @default.
- W2890128393 hasRelatedWork W2099085467 @default.
- W2890128393 hasRelatedWork W2185893991 @default.
- W2890128393 hasRelatedWork W2290776461 @default.
- W2890128393 hasRelatedWork W2761748950 @default.
- W2890128393 hasRelatedWork W2768404925 @default.
- W2890128393 hasRelatedWork W2789844390 @default.
- W2890128393 hasRelatedWork W2805984568 @default.
- W2890128393 hasRelatedWork W2885574771 @default.
- W2890128393 hasRelatedWork W2912907958 @default.
- W2890128393 hasRelatedWork W2952464168 @default.
- W2890128393 hasRelatedWork W2963945982 @default.
- W2890128393 hasRelatedWork W3105355360 @default.
- W2890128393 hasRelatedWork W3212981206 @default.
- W2890128393 hasRelatedWork W42320735 @default.
- W2890128393 hasRelatedWork W2109528881 @default.
- W2890128393 hasRelatedWork W2959474188 @default.
- W2890128393 hasRelatedWork W3012446380 @default.
- W2890128393 isParatext "false" @default.
- W2890128393 isRetracted "false" @default.
- W2890128393 magId "2890128393" @default.
- W2890128393 workType "article" @default.