Matches in SemOpenAlex for { <https://semopenalex.org/work/W3031036324> ?p ?o ?g. }
Showing items 1 to 75 of
75
with 100 items per page.
- W3031036324 startingPage "79" @default.
- W3031036324 abstract "Abstract If two or more identical HTTPS clients, located at different geographic locations (regions), make an HTTPS request to the same domain (e.g. example.com ), on the same day, will they receive the same HTTPS security guarantees in response? Our results give evidence that this is not always the case. We conduct scans for the top 250000 most visited domains on the Internet, from clients located at five different regions: Australia, Brazil, India, the UK, and the US. Our scans gather data from both application (URLs and HTTP headers) and transport (servers’ selected TLS version, ciphersuite, and certificate) layers. Overall, we find that HTTPS inconsistencies at the application layer are higher than those at the transport layer. We also find that HTTPS security inconsistencies are strongly related to URLs and IPs diversity among regions, and to a lesser extent to the presence of redirections. Further manual inspection shows that there are several reasons behind URLs diversity among regions such as downgrading to the plain-HTTP protocol, using different subdomains, different TLDs, or different home page documents. Furthermore, we find that downgrading to plain-HTTP is related to websites’ regional blocking. We also provide attack scenarios that show how an attacker can benefit from HTTPS security inconsistencies, and introduce a new attack scenario which we call the “region confusion” attack. Finally, based on our analysis and observations, we provide discussion, which include some recommendations such as the need for testing tools for domain administrators and users that help to mitigate and detect regional domains’ inconsistencies, standardising regional domains format with the same-origin policy (of domains) in mind, standardising secure URL redirections, and avoid redirections whenever possible." @default.
- W3031036324 created "2020-06-05" @default.
- W3031036324 creator A5030231646 @default.
- W3031036324 creator A5054220744 @default.
- W3031036324 creator A5084476168 @default.
- W3031036324 date "2020-01-01" @default.
- W3031036324 modified "2023-09-27" @default.
- W3031036324 title "Exploring HTTPS Security Inconsistencies: A Cross-Regional Perspective." @default.
- W3031036324 hasPublicationYear "2020" @default.
- W3031036324 type Work @default.
- W3031036324 sameAs 3031036324 @default.
- W3031036324 citedByCount "0" @default.
- W3031036324 crossrefType "journal-article" @default.
- W3031036324 hasAuthorship W3031036324A5030231646 @default.
- W3031036324 hasAuthorship W3031036324A5054220744 @default.
- W3031036324 hasAuthorship W3031036324A5084476168 @default.
- W3031036324 hasConcept C110875604 @default.
- W3031036324 hasConcept C11171543 @default.
- W3031036324 hasConcept C134306372 @default.
- W3031036324 hasConcept C136764020 @default.
- W3031036324 hasConcept C148176105 @default.
- W3031036324 hasConcept C15744967 @default.
- W3031036324 hasConcept C2781140086 @default.
- W3031036324 hasConcept C33923547 @default.
- W3031036324 hasConcept C36503486 @default.
- W3031036324 hasConcept C38652104 @default.
- W3031036324 hasConcept C41008148 @default.
- W3031036324 hasConcept C77088390 @default.
- W3031036324 hasConcept C80444323 @default.
- W3031036324 hasConcept C93996380 @default.
- W3031036324 hasConcept C96865113 @default.
- W3031036324 hasConceptScore W3031036324C110875604 @default.
- W3031036324 hasConceptScore W3031036324C11171543 @default.
- W3031036324 hasConceptScore W3031036324C134306372 @default.
- W3031036324 hasConceptScore W3031036324C136764020 @default.
- W3031036324 hasConceptScore W3031036324C148176105 @default.
- W3031036324 hasConceptScore W3031036324C15744967 @default.
- W3031036324 hasConceptScore W3031036324C2781140086 @default.
- W3031036324 hasConceptScore W3031036324C33923547 @default.
- W3031036324 hasConceptScore W3031036324C36503486 @default.
- W3031036324 hasConceptScore W3031036324C38652104 @default.
- W3031036324 hasConceptScore W3031036324C41008148 @default.
- W3031036324 hasConceptScore W3031036324C77088390 @default.
- W3031036324 hasConceptScore W3031036324C80444323 @default.
- W3031036324 hasConceptScore W3031036324C93996380 @default.
- W3031036324 hasConceptScore W3031036324C96865113 @default.
- W3031036324 hasLocation W30310363241 @default.
- W3031036324 hasOpenAccess W3031036324 @default.
- W3031036324 hasPrimaryLocation W30310363241 @default.
- W3031036324 hasRelatedWork W1579366785 @default.
- W3031036324 hasRelatedWork W1964181392 @default.
- W3031036324 hasRelatedWork W2046015955 @default.
- W3031036324 hasRelatedWork W2295359938 @default.
- W3031036324 hasRelatedWork W2407175046 @default.
- W3031036324 hasRelatedWork W2551436658 @default.
- W3031036324 hasRelatedWork W2567470805 @default.
- W3031036324 hasRelatedWork W2769724253 @default.
- W3031036324 hasRelatedWork W2788125071 @default.
- W3031036324 hasRelatedWork W2883994809 @default.
- W3031036324 hasRelatedWork W2889478221 @default.
- W3031036324 hasRelatedWork W2895807258 @default.
- W3031036324 hasRelatedWork W2954474896 @default.
- W3031036324 hasRelatedWork W2975725747 @default.
- W3031036324 hasRelatedWork W3012038311 @default.
- W3031036324 hasRelatedWork W3045410775 @default.
- W3031036324 hasRelatedWork W3094517308 @default.
- W3031036324 hasRelatedWork W3103054415 @default.
- W3031036324 hasRelatedWork W3133848745 @default.
- W3031036324 hasRelatedWork W3205434230 @default.
- W3031036324 hasVolume "2020" @default.
- W3031036324 isParatext "false" @default.
- W3031036324 isRetracted "false" @default.
- W3031036324 magId "3031036324" @default.
- W3031036324 workType "article" @default.