2009 International Conference on Advanced Information Networking and Applications Workshops Cipher Suite Setting Problem of SSL Protocol and it's Solutions Bradford, United Kingdom May 26-May 29 ISBN: 978-0-7695-3639-2
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/WAINA.2009.76
As the use of Internet is being generalized, the security problems about data transfer are rearing up as the important issue. There are many security protocols to solve the problems and the SSL (Secure Socket layer) protocol is the most widely used one among them. While the SSL protocol is designed to defend the client from active attacks such as message forgery and message alteration, the cipher suite setting can be easily modified. If the attacker draws on a malfunction of the client system and modifies the software's cipher suite setting to the symmetric key algorithm which has short key length, he can eavesdrop and cryptanalyze the encrypted data. In this paper, we examine the web sites whether they generate the security session through the symmetric key algorithm which has short key length and propose the solution of the cipher suite setting problem.
Index Terms:
SSL, Secure Socket Layer, Cipher Suite, Security
Citation:
Yoonyoung Lee, Soonhaeng Hur, Dongho Won, Seungjoo Kim, "Cipher Suite Setting Problem of SSL Protocol and it's Solutions," waina, pp.140-146, 2009 International Conference on Advanced Information Networking and Applications Workshops, 2009 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||