Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said

Mohd Jawi @ Said, Suhairi (2017) Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said. Masters thesis, Universiti Teknologi MARA (UiTM).

Abstract

Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-intrusive proxy technique that merges this gap. The first part of this study discusses the components of the proposed proxy which handles two categories of attributes classified as static or dynamic. These attributes are compared against a set of policies written in JavaScript Object Notation (JSON). Second part of this study considers the practical implementation of this proxy for monitoring both SSL/TLS certificates and-connection properties in between web browsers and SSL/TLS web server. It moderates the ongoing and subsequent SSL/TLS sessions from clients that proxy serves. This proxy can be considered as a localized notary with single path probing as compared to other notary services which use the concept of multipath probing via multiple network vantage points. Benefit of this work will be demonstrated as a simpler implementation for clients who have no effective means to authenticate and secure HTTPS connection except provided by the browser. The proxy successfully detects and warns some well-known issues regarding SSL/TLS although it may miss some SSL/TLS issues that require intensive and time consuming analysis such provided by Qualys' SSL Server Test.

Metadata

Item Type: Thesis (Masters)
Creators:
Creators
Email / ID Num.
Mohd Jawi @ Said, Suhairi
2010124045
Contributors:
Contribution
Name
Email / ID Num.
Thesis advisor
Mohd Ali, Fakariah Hani
UNSPECIFIED
Divisions: Universiti Teknologi MARA, Shah Alam > Faculty of Computer and Mathematical Sciences
Programme: Master of Science (Information Technology and Quantitative Sciences)-CS780
Keywords: HTTPS, JSON, proxy
Date: 2017
URI: https://ir.uitm.edu.my/id/eprint/37205
Edit Item
Edit Item

Download

[thumbnail of 37205.pdf] Text
37205.pdf

Download (153kB)

Digital Copy

Digital (fulltext) is available at:

Physical Copy

Physical status and holdings:
Item Status:
On Shelf

ID Number

37205

Indexing

Statistic

Statistic details