Prevention Techniques for SSL Hacking Threats to E-Government Services

Volume: 7 Number: 2 June 1, 2018
  • Ahmet Efe
  • Rıdvan Tekdoğan

Prevention Techniques for SSL Hacking Threats to E-Government Services

Abstract

Since security threats increase over time, security of internet commination has to be achieved with cryptography and ciphering techniques. The use of SSL protocols secures our communication between intended hosts and clients. As a legislative requirement it is obligatory for all government organizations and e-government applications to use SSL secure socked layer which ensures encrypted information transmission. Without use of SSL anyone who captures the IP packet can observe the communication since communication channels transmit bare information. Whilst securing the communication preserves secrets, sometimes it threatens business, human rights and government sovereignty. Employees can transfer confidential data to third parties over a secure channel using their credentials and authorized certificates. Therefore to secure business and e-government, decryption of SSL is obligatory to detect malevolent users. Considering the ever widening usage of internet infrastructure for e-government services and e-government applications, securing sensitive and critical information from unauthorized and malicious parties via SSL protocols which are hardened against MITM attacks became a major concern. Furthermore, usage of blockchain technology and increasing volume of cryptocurrencies are some of other issues related to security of assets over internet. In this paper, we have surveyed the SSL hacking methods and prevention techniques to have a clear vision of threats and remedies. Since hacking have several stages from ARP poisoning to fake certificate, prevention techniques are focused on different levels.

Keywords

References

  1. [1] H. Seung-Woo, et al. "A survey on MITM and its countermeasures in the TLS handshake protocol." Ubiquitous and Future Networks (ICUFN), 2016, Eighth International Conference on. IEEE. 11-12.
  2. [2] O. Eisen, "Catching the fraudulent Man-in-the-Middle and Man-in-the-Browser." 2010, Network Security.
  3. [3] T. Chomsiri, "HTTPS Hacking Protection." Advanced Information Networking and Applications Workshops, 2007, AINAW'07. 21st International Conference on. Vol. 1. IEEE.
  4. [4] N. Seung Yeob, S. Djuraev, and M. Park. "Collaborative approach to mitigating ARP poisoningbased Man-in-the-Middle attacks." Computer Networks 57.18 2013, pp. 3866-3884.
  5. [5] D. Italo, M. Ahamad, and P. Traynor. "POSTER: Trust No One Else: Detecting MITM Attacks Against SSL/TLS Without Third-Parties." pp 199-216
  6. [6] L. Wu, et al. "SSL-DP: a rootkit of network based SSL and TLS traffic decryptor." Cybercrime and Trustworthy Computing Workshop (CTC), 2010 Second. IEEE.
  7. [7] D. Jiang, X. Li, and H. Huang. "A study of man-in-themiddle attack based on SSL certificate interaction." Instrumentation, Measurement, Computer, Communication and Control, 2011, First International Conference on IEEE.
  8. [8] O. Rolf, R. Hauser, and D. Basin. "SSL/TLS sessionaware user authentication–Or how to effectively thwart the man-in-the-middle." Computer Communications 29.12, 2006, 2238-2246.

Details

Primary Language

English

Subjects

-

Journal Section

-

Authors

Ahmet Efe This is me

Rıdvan Tekdoğan This is me

Publication Date

June 1, 2018

Submission Date

-

Acceptance Date

-

Published in Issue

Year 2018 Volume: 7 Number: 2

APA
Efe, A., & Tekdoğan, R. (2018). Prevention Techniques for SSL Hacking Threats to E-Government Services. International Journal of Information Security Science, 7(2), 67-77. https://izlik.org/JA94SS66RA
AMA
1.Efe A, Tekdoğan R. Prevention Techniques for SSL Hacking Threats to E-Government Services. IJISS. 2018;7(2):67-77. https://izlik.org/JA94SS66RA
Chicago
Efe, Ahmet, and Rıdvan Tekdoğan. 2018. “Prevention Techniques for SSL Hacking Threats to E-Government Services”. International Journal of Information Security Science 7 (2): 67-77. https://izlik.org/JA94SS66RA.
EndNote
Efe A, Tekdoğan R (June 1, 2018) Prevention Techniques for SSL Hacking Threats to E-Government Services. International Journal of Information Security Science 7 2 67–77.
IEEE
[1]A. Efe and R. Tekdoğan, “Prevention Techniques for SSL Hacking Threats to E-Government Services”, IJISS, vol. 7, no. 2, pp. 67–77, June 2018, [Online]. Available: https://izlik.org/JA94SS66RA
ISNAD
Efe, Ahmet - Tekdoğan, Rıdvan. “Prevention Techniques for SSL Hacking Threats to E-Government Services”. International Journal of Information Security Science 7/2 (June 1, 2018): 67-77. https://izlik.org/JA94SS66RA.
JAMA
1.Efe A, Tekdoğan R. Prevention Techniques for SSL Hacking Threats to E-Government Services. IJISS. 2018;7:67–77.
MLA
Efe, Ahmet, and Rıdvan Tekdoğan. “Prevention Techniques for SSL Hacking Threats to E-Government Services”. International Journal of Information Security Science, vol. 7, no. 2, June 2018, pp. 67-77, https://izlik.org/JA94SS66RA.
Vancouver
1.Ahmet Efe, Rıdvan Tekdoğan. Prevention Techniques for SSL Hacking Threats to E-Government Services. IJISS [Internet]. 2018 Jun. 1;7(2):67-7. Available from: https://izlik.org/JA94SS66RA