Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said

Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-int...

Full description

Saved in:
Bibliographic Details
Main Author: Mohd Jawi @ Said, Suhairi
Format: Thesis
Language:English
Published: 2017
Online Access:https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-uitm-ir.37205
record_format uketd_dc
spelling my-uitm-ir.372052023-08-21T02:47:22Z Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said 2017 Mohd Jawi @ Said, Suhairi Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-intrusive proxy technique that merges this gap. The first part of this study discusses the components of the proposed proxy which handles two categories of attributes classified as static or dynamic. These attributes are compared against a set of policies written in JavaScript Object Notation (JSON). Second part of this study considers the practical implementation of this proxy for monitoring both SSL/TLS certificates and-connection properties in between web browsers and SSL/TLS web server. It moderates the ongoing and subsequent SSL/TLS sessions from clients that proxy serves. This proxy can be considered as a localized notary with single path probing as compared to other notary services which use the concept of multipath probing via multiple network vantage points. Benefit of this work will be demonstrated as a simpler implementation for clients who have no effective means to authenticate and secure HTTPS connection except provided by the browser. The proxy successfully detects and warns some well-known issues regarding SSL/TLS although it may miss some SSL/TLS issues that require intensive and time consuming analysis such provided by Qualys' SSL Server Test. 2017 Thesis https://ir.uitm.edu.my/id/eprint/37205/ https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf text en public masters Universiti Teknologi MARA (UiTM) Faculty of Computer & Mathematical Sciences Mohd Ali, Fakariah Hani
institution Universiti Teknologi MARA
collection UiTM Institutional Repository
language English
advisor Mohd Ali, Fakariah Hani
description Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-intrusive proxy technique that merges this gap. The first part of this study discusses the components of the proposed proxy which handles two categories of attributes classified as static or dynamic. These attributes are compared against a set of policies written in JavaScript Object Notation (JSON). Second part of this study considers the practical implementation of this proxy for monitoring both SSL/TLS certificates and-connection properties in between web browsers and SSL/TLS web server. It moderates the ongoing and subsequent SSL/TLS sessions from clients that proxy serves. This proxy can be considered as a localized notary with single path probing as compared to other notary services which use the concept of multipath probing via multiple network vantage points. Benefit of this work will be demonstrated as a simpler implementation for clients who have no effective means to authenticate and secure HTTPS connection except provided by the browser. The proxy successfully detects and warns some well-known issues regarding SSL/TLS although it may miss some SSL/TLS issues that require intensive and time consuming analysis such provided by Qualys' SSL Server Test.
format Thesis
qualification_level Master's degree
author Mohd Jawi @ Said, Suhairi
spellingShingle Mohd Jawi @ Said, Suhairi
Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
author_facet Mohd Jawi @ Said, Suhairi
author_sort Mohd Jawi @ Said, Suhairi
title Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_short Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_full Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_fullStr Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_full_unstemmed Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_sort nonintrusive ssl/tls proxy technique with json-based policy / suhairi mohd jawi @ said
granting_institution Universiti Teknologi MARA (UiTM)
granting_department Faculty of Computer & Mathematical Sciences
publishDate 2017
url https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf
_version_ 1783734400902496256