Lost in TLS? No More! Assisted Deployment of Secure TLS Configurations - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Lost in TLS? No More! Assisted Deployment of Secure TLS Configurations

Résumé

Over the last few years, there has been an almost exponential growth of TLS popularity and usage, especially among applications that deal with sensitive data. However, even with this widespread use, TLS remains for many system administrators a complex subject. The main reason is that they do not have the time to understand all the cryptographic algorithms and features used in a TLS suite and their relative weaknesses. For these reasons, many different tools have been developed to verify TLS implementations. However, they usually analyze the TLS configuration and provide a list of possible attacks, without specifying their mitigations. In this paper, we present TLSAssistant, a fully-featured tool that combines state-of-the-art TLS analyzers with a report system that suggests appropriate mitigations and shows the full set of viable attacks.
Fichier principal
Vignette du fichier
480962_1_En_11_Chapter.pdf (644.88 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02384588 , version 1 (28-11-2019)

Licence

Paternité

Identifiants

Citer

Salvatore Manfredi, Silvio Ranise, Giada Sciarretta. Lost in TLS? No More! Assisted Deployment of Secure TLS Configurations. 33th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), Jul 2019, Charleston, SC, United States. pp.201-220, ⟨10.1007/978-3-030-22479-0_11⟩. ⟨hal-02384588⟩
61 Consultations
104 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More