Download presentation
Presentation is loading. Please wait.
Published bySylvia Skinner Modified over 9 years ago
1
Cryptography and Network Security Chapter 16 Fifth Edition by William Stallings Lecture slides by Lawrie Brown
2
Web Security Issues u Original Internet protocols do not have built-in security (IP, TCP, HTTP,... ) u Many threats arise for web and other Internet applications u Issues at: client, server and traffic between client and server u Cover: SSL/TLS, SSH, IPsec
3
A Comparison of Threats on the Web
4
Web Traffic Security Approaches u IPsec: Security for IP datagrams; general solution for all Internet traffic; implemented in OS
5
Web Traffic Security Approaches u SSL/TLS: Security for TCP segments; general solution for all TCP-based applications; implemented in libraries/applications (e.g. OpenSSL)
6
Web Traffic Security Approaches u Application-specific: Security for application messages; specific to each applications; implemented in single application
7
SSL (Secure Socket Layer) u Secure Sockets Layer (SSL) originated in Netscape web browser u Transport Layer Security (TLS) standardised by IETF u SSLv3 and TLS are almost the same u SSL provides security services to application layer protocols using TCP u SSL architecture consists of multiple protocols
8
SSL Architecture u Record: provides confidentiality and message integrity u Handshake: authenticate entities, negotiate parameter values u Change Cipher: change cipher for use in connection u Alert: alert peer entity of status/warning/error
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.