基于Bettercap工具的HTTP严格传输安全(HSTS)配置与实现符合性分析

A. Amiruddin, Daffa Akbar Putra Yusa, Rizky Ainur Rofiq
{"title":"基于Bettercap工具的HTTP严格传输安全(HSTS)配置与实现符合性分析","authors":"A. Amiruddin, Daffa Akbar Putra Yusa, Rizky Ainur Rofiq","doi":"10.1109/ICIMCIS53775.2021.9699358","DOIUrl":null,"url":null,"abstract":"Currently, HTTPS is commonly used because it offers more protection when compared to HTTP. However, it does not rule out the possibility of attacks being carried out against HTTPS. One of the features that can improve HTTPS security is configuring HTTP strict transport security (HSTS). Unfortunately, not all HSTS is successfully configured and implemented correctly due to administrator ignorance. The purpose of this study is to provide an overview of what configurations need to be done to run HSTS properly to increase the functionality of existing features and improve security. Configuration conformity testing is done using three parameters, i.e., max-age, includeSubDomains, and preload. The attack attempts carried out in this exploratory study used Bettercap, which allows multiple types of attacks to be carried out simultaneously. The results obtained from this study include a list of parameters that need to be met as a condition of an adequately configured HSTS on a website, such as the max-age value, which has a minimum value of 31536000.","PeriodicalId":250460,"journal":{"name":"2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Conformity Analysis of HTTP Strict Transport Security (HSTS) Configuration and Implementation Using Bettercap Tools\",\"authors\":\"A. Amiruddin, Daffa Akbar Putra Yusa, Rizky Ainur Rofiq\",\"doi\":\"10.1109/ICIMCIS53775.2021.9699358\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Currently, HTTPS is commonly used because it offers more protection when compared to HTTP. However, it does not rule out the possibility of attacks being carried out against HTTPS. One of the features that can improve HTTPS security is configuring HTTP strict transport security (HSTS). Unfortunately, not all HSTS is successfully configured and implemented correctly due to administrator ignorance. The purpose of this study is to provide an overview of what configurations need to be done to run HSTS properly to increase the functionality of existing features and improve security. Configuration conformity testing is done using three parameters, i.e., max-age, includeSubDomains, and preload. The attack attempts carried out in this exploratory study used Bettercap, which allows multiple types of attacks to be carried out simultaneously. The results obtained from this study include a list of parameters that need to be met as a condition of an adequately configured HSTS on a website, such as the max-age value, which has a minimum value of 31536000.\",\"PeriodicalId\":250460,\"journal\":{\"name\":\"2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS\",\"volume\":\"4 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICIMCIS53775.2021.9699358\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIMCIS53775.2021.9699358","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

目前,HTTPS被广泛使用,因为与HTTP相比,它提供了更多的保护。然而,这并不排除针对HTTPS进行攻击的可能性。可以提高HTTPS安全性的特性之一是配置HTTP严格传输安全(HSTS)。不幸的是,由于管理员的疏忽,并非所有HSTS都能成功配置和正确实现。本研究的目的是概述需要进行哪些配置才能正确运行HSTS,以增加现有特性的功能并提高安全性。配置一致性测试是使用三个参数完成的,即max-age、inclesubdomains和preload。在本探索性研究中进行的攻击尝试使用了Bettercap,它允许同时进行多种类型的攻击。本研究得到的结果包括一个网站上充分配置HSTS所需满足的参数列表,如max-age值,其最小值为31536000。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Conformity Analysis of HTTP Strict Transport Security (HSTS) Configuration and Implementation Using Bettercap Tools
Currently, HTTPS is commonly used because it offers more protection when compared to HTTP. However, it does not rule out the possibility of attacks being carried out against HTTPS. One of the features that can improve HTTPS security is configuring HTTP strict transport security (HSTS). Unfortunately, not all HSTS is successfully configured and implemented correctly due to administrator ignorance. The purpose of this study is to provide an overview of what configurations need to be done to run HSTS properly to increase the functionality of existing features and improve security. Configuration conformity testing is done using three parameters, i.e., max-age, includeSubDomains, and preload. The attack attempts carried out in this exploratory study used Bettercap, which allows multiple types of attacks to be carried out simultaneously. The results obtained from this study include a list of parameters that need to be met as a condition of an adequately configured HSTS on a website, such as the max-age value, which has a minimum value of 31536000.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信