Secure inspection of web transactions

  • Authors:
  • Mika Rautila;Jani Suomalainen

  • Affiliations:
  • VTT Technical Research Centre of Finland, Vuorimiehentie 3, Espoo, Finland;VTT Technical Research Centre of Finland, Vuorimiehentie 3, Espoo, Finland

  • Venue:
  • International Journal of Internet Technology and Secured Transactions
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Web transactions are vulnerable for attacks where malicious software has infected a browser or where a root certifier has been compromised. As a countermeasure, we intercept HTTPS traffic in order to authorise certifiers as well as to inspect, verify and complement transactions securely. The interception and inspection is done in a trusted device, outside potentially compromised PC and browser. We propose a novel and flexible mechanism for controlling interception dynamically with directives embedded into HTML documents. We limit the authority of root certifiers over critical services with site-specific certification rules. We propose different models for realising the interceptor concept. The feasibility of the proposals is demonstrated by implementing and deploying interception into a USB gadget and a mobile phone.