Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
Stefano Calzavara, Riccardo Focardi, Matús Nemec, Alvise Rabitti, Marco Squarcina
摘要
HTTPS aims at securing communication over the Web by providing a cryptographic protection layer that ensures the confidentiality and integrity of communication and enables client/server authentication. However, HTTPS is based on the SSL/TLS protocol suites that have been shown to be vulnerable to various attacks in the years. This has required fixes and mitigations both in the servers and in the browsers, producing a complicated mixture of protocol versions and implementations in the wild, which makes it unclear which attacks are still effective on the modern Web and what is their import on web application security. In this paper, we present the first systematic quantitative evaluation of web application insecurity due to cryptographic vulnerabilities. We specify attack conditions against TLS using attack trees and we crawl the Alexa Top 10k to assess the import of these issues on page integrity, authentication credentials and web tracking. Our results show that the security of a consistent number of websites is severely harmed by cryptographic weaknesses that, in many cases, are due to external or related-domain hosts. This empirically, yet systematically demonstrates how a relatively limited number of exploitable HTTPS vulnerabilities are amplified by the complexity of the web ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 被引用 56 次
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 被引用 25 次
- Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile BrowsersBrian Kondracki, Assel Aliyeva, Manuel Egele, Jason Polakis 等S&P 2020 · 被引用 13 次
- Understanding and Detecting Abused Image Hosting Modules as Malicious ServicesGeng Hong, Mengying Wu, Pei Chen, Xiaojing Liao 等CCS 2023 · 被引用 3 次
- You Get What You Sample: Evaluating Sampling Strategies for Web Security MeasurementsXuenan Zhang, Yuqing Yang, Giancarlo PellegrinoCCS 2026
它引用的顶会 Paper17
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes 等NDSS 2017 · 被引用 161 次
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
相关 Paper
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young 等USENIX Security 2019 · 被引用 27 次
- ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS AuthenticationMarcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak 等USENIX Security 2021 · 被引用 20 次
- Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksMingming Zhang, Xiaofeng Zheng, Kaiwen Shen, Ziqiao Kong 等CCS 2020 · 被引用 15 次
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLSRobert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel 等USENIX Security 2026
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 被引用 86 次
