Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said

Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-int...

Full description

Saved in:
Bibliographic Details
Main Author: Mohd Jawi @ Said, Suhairi
Format: Thesis
Language:English
Published: 2017
Online Access:https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf
https://ir.uitm.edu.my/id/eprint/37205/
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.uitm.ir.37205
record_format eprints
spelling my.uitm.ir.372052023-08-21T02:47:22Z https://ir.uitm.edu.my/id/eprint/37205/ Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said Mohd Jawi @ Said, Suhairi Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-intrusive proxy technique that merges this gap. The first part of this study discusses the components of the proposed proxy which handles two categories of attributes classified as static or dynamic. These attributes are compared against a set of policies written in JavaScript Object Notation (JSON). Second part of this study considers the practical implementation of this proxy for monitoring both SSL/TLS certificates and-connection properties in between web browsers and SSL/TLS web server. It moderates the ongoing and subsequent SSL/TLS sessions from clients that proxy serves. This proxy can be considered as a localized notary with single path probing as compared to other notary services which use the concept of multipath probing via multiple network vantage points. Benefit of this work will be demonstrated as a simpler implementation for clients who have no effective means to authenticate and secure HTTPS connection except provided by the browser. The proxy successfully detects and warns some well-known issues regarding SSL/TLS although it may miss some SSL/TLS issues that require intensive and time consuming analysis such provided by Qualys' SSL Server Test. 2017 Thesis NonPeerReviewed text en https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said. (2017) Masters thesis, thesis, Universiti Teknologi MARA (UiTM).
institution Universiti Teknologi Mara
building Tun Abdul Razak Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Mara
content_source UiTM Institutional Repository
url_provider http://ir.uitm.edu.my/
language English
description Certificate and SSL/TLS connections are two security aspects needs to be handled simultaneously in HTTPS. Some previous studies focused more on trust relationship in certificates whereas the properties of SSL/TLS connections were more prevalent in SSL/TLS surveys. Thus, this study proposes a non-intrusive proxy technique that merges this gap. The first part of this study discusses the components of the proposed proxy which handles two categories of attributes classified as static or dynamic. These attributes are compared against a set of policies written in JavaScript Object Notation (JSON). Second part of this study considers the practical implementation of this proxy for monitoring both SSL/TLS certificates and-connection properties in between web browsers and SSL/TLS web server. It moderates the ongoing and subsequent SSL/TLS sessions from clients that proxy serves. This proxy can be considered as a localized notary with single path probing as compared to other notary services which use the concept of multipath probing via multiple network vantage points. Benefit of this work will be demonstrated as a simpler implementation for clients who have no effective means to authenticate and secure HTTPS connection except provided by the browser. The proxy successfully detects and warns some well-known issues regarding SSL/TLS although it may miss some SSL/TLS issues that require intensive and time consuming analysis such provided by Qualys' SSL Server Test.
format Thesis
author Mohd Jawi @ Said, Suhairi
spellingShingle Mohd Jawi @ Said, Suhairi
Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
author_facet Mohd Jawi @ Said, Suhairi
author_sort Mohd Jawi @ Said, Suhairi
title Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_short Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_full Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_fullStr Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_full_unstemmed Nonintrusive SSL/TLS proxy technique with JSON-based policy / Suhairi Mohd Jawi @ Said
title_sort nonintrusive ssl/tls proxy technique with json-based policy / suhairi mohd jawi @ said
publishDate 2017
url https://ir.uitm.edu.my/id/eprint/37205/1/37205.pdf
https://ir.uitm.edu.my/id/eprint/37205/
_version_ 1775626299239301120
score 13.211869