Triple Handshakes and Cookie Cutters: Breaking and Fixing Authentication over TLS (original) (raw)
Related papers
SSL/TLS session-aware user authentication – Or how to effectively thwart the man-in-the-middle
Computer Communications, 2006
Attacking RSA-Based Sessions in SSL/TLS
2003
A Modular Security Analysis of the TLS Handshake Protocol
Lecture Notes in Computer Science, 2008
The TLS Handshake Protocol: A Modular Analysis
Journal of Cryptology, 2010
SSL/TLS session-aware user authentication revisited
Computers & Security, 2008
LURK: Server-Controlled TLS Delegation
2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
Provably secure browser-based user-aware mutual authentication over TLS
Proceedings of the 2008 ACM symposium on Information, computer and communications security - ASIACCS '08, 2008
VULNERABILITIES OF THE SSL/TLS PROTOCOL
Jelena Ćurguz, Computer Science & Information Technology (CS & IT) Computer Science Conference Proceedings (CSCP)
Man in The Middle Attacks Against SSL/TLS: Mitigation and Defeat
Journal of Cyber Security and Mobility
Improving the Secure Socket Layer Protocol by modifying its Authentication function
Ramzi Haraty, Abdul-Nasser El-Kassar
2006 World Automation Congress, 2006
Session Initiation Protocol Attacks and Challenges
Universally Composable Security Analysis of TLS
Lecture Notes in Computer Science, 2008
Survey of the Protection Mechanisms to the SSL-based Session Hijacking Attacks
Network Protocols and Algorithms
Exchanging Demands: Weaknesses in SSL Implemenations for Mobile Platforms
The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software
2013
Towards securing client-server connections against man-in-the-middle attacks
2012 10th International Symposium on Electronics and Telecommunications, 2012
A STUDY OF THE SSL AND BACKDOOR BASED ATTACKS IN NETWORK ENVIRONMENTS
SKIREC Publication- UGC Approved Journals
Off-Path Hacking: The Illusion of Challenge-Response Authentication
IEEE Secur. Privacy
On Establishing and Fixing a Parallel Session Attack in a Security Protocol
2008
KEERTHI VASAN K KEERTHI VASAN K
International Journal of Computer Network and Information Security, 2016
SSL/TLS Session-Aware User Authentication
Computer, 2000
A Proof of Concept Implementation of SSL/TLS Session-Aware User Authentication (TLS-SA)
Informatik aktuell, 2007
WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring
Attacks to a proxy-mediated key agreement protocol based on symmetric encryption
IACR Cryptol. ePrint Arch., 2016