YoVDO

Postcards from the Post HTTP World - Amplification of HTTPS Vulnerabilities in the Web Ecosystem

Offered By: IEEE via YouTube

Tags

Web Application Security Courses Data Collection Courses Cryptographic Vulnerabilities Courses

Course Description

Overview

Explore a comprehensive analysis of HTTPS vulnerabilities and their impact on web application security in this 20-minute IEEE conference talk. Delve into the complexities of SSL/TLS protocol suites and their susceptibility to various attacks. Examine the first systematic quantitative evaluation of web application insecurity due to cryptographic vulnerabilities, focusing on the Alexa Top 10k websites. Discover how attack trees are used to specify conditions against TLS and assess the implications for page integrity, authentication credentials, and web tracking. Gain insights into how a limited number of exploitable HTTPS vulnerabilities are amplified by the intricacies of the web ecosystem, affecting the security of numerous websites due to external or related-domain hosts.

Syllabus

Intro
A dirge for HTTP
But can we trust HTTPS?
Vulnerability amplification
Contributions
Attack trees for TLS security
Data collection
Preliminary statistics
Page integrity
Cookies: results
Closing remarks


Taught by

IEEE Symposium on Security and Privacy

Tags

Related Courses

Observing and Analysing Performance in Sport
OpenLearning
Statistics: Making Sense of Data
University of Toronto via Coursera
Financial Planning
TAFE NSW via Open2Study
Mobiles for Development
Indian Institute of Technology Kanpur via Independent
Valoración de futbolistas
Universitat Politècnica de València via UPV [X]