A new scheme with secure cookie against SSLStrip attack

  • Authors:
  • Sendong Zhao;Wu Yang;Ding Wang;Wenzhen Qiu

  • Affiliations:
  • Information Security Research Center, Harbin Engineering University, Harbin City, China;Information Security Research Center, Harbin Engineering University, Harbin City, China;College of Computer Science and Technology, Harbin Engineering University, Harbin City, China;China Telecom Co., Ltd. Fuzhou Branch, Fuzhou City, China

  • Venue:
  • WISM'12 Proceedings of the 2012 international conference on Web Information Systems and Mining
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

In 2009 Moxie Marlinspike proposed a new Man-in-the- Middle (MitM) attack on secure socket layer (SSL) called SSLStrip attack at Black Hat DC, which is a serious threat to Web users. Some solutions have been proposed in literature. However, until now there is no practical countermeasure to resist on such attack. In this paper, we propose a new scheme to defend against SSLStrip attack by improving the previous secure cookie protocols and using proxy pattern and reverse proxy pattern. It implements a secure LAN guaranteed proxy in client-side, a secure server guaranteed proxy in server-side and a cookie authentication mechanism to provide the following security services: source authentication, integrity control and defending SSLStrip attack.