The Experts below are selected from a list of 6096 Experts worldwide ranked by ideXlab platform
Shigekoto Kaihara - One of the best experts on this subject based on the ideXlab platform.
-
C-HTTP-the development of a secure, closed HTTP-based network on the Internet
Proceedings of Internet Society Symposium on Network and Distributed Systems Security, 1996Co-Authors: Takaaki Kiuchi, Shigekoto KaiharaAbstract:We have designed "C-HTTP" which provides secure HTTP communication mechanisms within a closed group of institutions on the Internet, where each member is protected by its own firewall. C-HTTP-based communications are made possible by the following three components: a client-side proxy, a sewer-side proxy and a C-HTTP name server. A client-side proxy and server-side proxy communicate with each other using a secure, Encrypted Protocol while communications between a user agent and client-side proxy or an origin sewer and sewer-side proxy are performed using current HTTP/1.0. In a C-HTTP-based network, instead of DNS, a C-HTTP-based secure, Encrypted name and certification service is used. The aim of C-HTTP is to assure institutional level security and is different in scope from other secure HTTP Protocols currently proposed which are oriented toward secure end-to-end HTTP communications in which security protection is dependent on each end-user.
Takaaki Kiuchi - One of the best experts on this subject based on the ideXlab platform.
-
C-HTTP-the development of a secure, closed HTTP-based network on the Internet
Proceedings of Internet Society Symposium on Network and Distributed Systems Security, 1996Co-Authors: Takaaki Kiuchi, Shigekoto KaiharaAbstract:We have designed "C-HTTP" which provides secure HTTP communication mechanisms within a closed group of institutions on the Internet, where each member is protected by its own firewall. C-HTTP-based communications are made possible by the following three components: a client-side proxy, a sewer-side proxy and a C-HTTP name server. A client-side proxy and server-side proxy communicate with each other using a secure, Encrypted Protocol while communications between a user agent and client-side proxy or an origin sewer and sewer-side proxy are performed using current HTTP/1.0. In a C-HTTP-based network, instead of DNS, a C-HTTP-based secure, Encrypted name and certification service is used. The aim of C-HTTP is to assure institutional level security and is different in scope from other secure HTTP Protocols currently proposed which are oriented toward secure end-to-end HTTP communications in which security protection is dependent on each end-user.
Torkveen, Kristian Helgesen - One of the best experts on this subject based on the ideXlab platform.
-
Internet Security Scanner
2021Co-Authors: Torkveen, Kristian HelgesenAbstract:The use of computers and networks in our daily lives is a fact at this point, and it is difficult to avoid interacting with computer systems and the internet. As more of our life depend on transmitting data over the internet, it's important that we can facilitate this data transmission in a secure manner. In short, this means ensuring that developers and applications have access to use secure Encrypted Protocols for communication, and that these Protocols are kept up to date and used in a proper manner. For the World Wide Web (WWW) and Hypertext Transfer Protocol (HTTP) the solution to facilitate this secure data transmission has become the Transport Layer Security (TLS) Encrypted Protocol, but the unEncrypted HTTP Protocol is still in use. Additionally, HTTP clients and servers implement several Protocol specific security measures in the form of HTTP headers. This presents a challenge. Considering the decentralized nature of the world wide web and the various independent servers hosting web applications, how can we monitor the adoption and support of various versions of the TLS Protocol and support for security features? In this thesis, I have created a scanner to monitor the use of TLS versions and various security features in the TLS and HTTP Protocols. The scanner is be designed to be extendable in order to allow collection of more data and analysis of collected data
Guizani M. - One of the best experts on this subject based on the ideXlab platform.
-
A Heuristic Statistical Testing Based Approach for Encrypted Network Traffic Identification
'Institute of Electrical and Electronics Engineers (IEEE)', 2019Co-Authors: Niu W., Zhuo Z., Zhang X., Du X., Yang G., Guizani M.Abstract:In recent years, malware with strong concealment uses Encrypted Protocol to evade detection. Thus, Encrypted traffic identification can help security analysts to be more effective in narrowing down those Encrypted network traffic. Existing methods are Protocol independent, such as statistical-based and machine-learning-based approaches. Statistical-based approaches, however, are confined to payload length and machine-learning-based approaches have a low recognition rate for Encrypted traffic using undisclosed Protocols. In this paper, we proposed a heuristic statistical testing (HST) approach that combines both statistics and machine learning and has been proved to alleviate their respective deficiencies. We manually selected four randomness tests to extract small payload features for machine learning to improve real-time performances. We also proposed a simple handshake skipping method called HST-R to increase the classification accuracy. We compared our approach with other identification approaches on a testing dataset consisting of traffic that uses two known, two undisclosed, and one custom cryptographic Protocols. Experimental results showed that HST-R performs better than other traditional coding-based, entropy-based, and ML-based approaches. We also showed that our handshake skipping method could generalize better for unknown cryptographic Protocols. Finally, we also conducted experimental comparisons among different classification algorithms. The results showed that C4.5, with our method, has the highest identification accuracy for secure sockets layer and secure shell traffic.Basic Research Programs of Sichuan Province, Science and Technology Foundation of State Grid Corporation of China, National Natural Science Foundation of ChinaScopu
Niu W. - One of the best experts on this subject based on the ideXlab platform.
-
A Heuristic Statistical Testing Based Approach for Encrypted Network Traffic Identification
'Institute of Electrical and Electronics Engineers (IEEE)', 2019Co-Authors: Niu W., Zhuo Z., Zhang X., Du X., Yang G., Guizani M.Abstract:In recent years, malware with strong concealment uses Encrypted Protocol to evade detection. Thus, Encrypted traffic identification can help security analysts to be more effective in narrowing down those Encrypted network traffic. Existing methods are Protocol independent, such as statistical-based and machine-learning-based approaches. Statistical-based approaches, however, are confined to payload length and machine-learning-based approaches have a low recognition rate for Encrypted traffic using undisclosed Protocols. In this paper, we proposed a heuristic statistical testing (HST) approach that combines both statistics and machine learning and has been proved to alleviate their respective deficiencies. We manually selected four randomness tests to extract small payload features for machine learning to improve real-time performances. We also proposed a simple handshake skipping method called HST-R to increase the classification accuracy. We compared our approach with other identification approaches on a testing dataset consisting of traffic that uses two known, two undisclosed, and one custom cryptographic Protocols. Experimental results showed that HST-R performs better than other traditional coding-based, entropy-based, and ML-based approaches. We also showed that our handshake skipping method could generalize better for unknown cryptographic Protocols. Finally, we also conducted experimental comparisons among different classification algorithms. The results showed that C4.5, with our method, has the highest identification accuracy for secure sockets layer and secure shell traffic.Basic Research Programs of Sichuan Province, Science and Technology Foundation of State Grid Corporation of China, National Natural Science Foundation of ChinaScopu