Chapter 6 - Transport-Level Security

Class: CSCE-465-63860


Table 6.1 A Comparison of Threats on the Web

Threats Consequences Countermeasures
Integrity -Modification of user data
-Trojan horse browser
-Modification of memory
-Modification of message traffic in transit
-Loss of information
-Compromise of machine
- Vulnerabilty to all other threats
Cryptographic checksums
Confidentiality -Eavesdropping on the net
-Theft of info from server
-Theft of data from client
-Info about network configuration
-Info about which client talks to server
-Loss of information
-Loss of privacy
Encryption, Web proxies
Denial of Service -Killing of user threads
-Flooding machine with bogus requests
● Filling up disk or memory
-Isolating machine by DNS attacks
-Disruptive
-Annoying
-Prevent user from getting work done
Difficult to prevent
Authentication -Impersonation of legitimate users
-Data forgery
-Misrepresentation of user
-Belief that false information is valid
Cryptographic techniques
Relative Location of Security Facilities in the TCP/IP Protocol Stack

image.png486

Note:

Transport Layer Security (TLS)

SSL/TLS Protocol Stack
image-1.png323

Notes:

TLS Architecture

Two important TLS concepts are:

A session state is defined by the following parameters:

A connection state is defined by the following parameters:

Notes:

The TLS Record Protocol

The TLS Record Protocol provides two services for TLS connections

Record Details:
image-2.png455x271

TLS Record Format
image-3.png456x427

TLS Record Protocol Payload
image-4.png449

TLS Handshake Protocol Message Types

Message Type Parameters
hello_request null
client_hello version, random, session id, cipher suite, compression method
server_hello version, random, session id, cipher suite, compression method
certificate chain of X.509v3 certificates
server_key_exchange parameters, signature
certificate_request type, authorities
server_done null
certificate_verify signature
client_key_exchange parameters, signature
finished hash value

Handshake Protocol Action
image-5.png464x609

Handshake Phase I

Notes:

Handshake Phase II

Notes:

Handshake Phase III

Notes:

Handshake Phase IV

Cryptographic Computations

Heartbeat Protocol

Notes:

TLS Attacks

Attack categories

Notes:

TLS Version 1.3

Notes:

image-7.png455

SSL/TLS Versions

image-6.png457x350

Notes:

image-8.png

Notes:

HTTPs (HTTP over TLS)

Connection Closure

Website Client Auth.

Secure Shell (SSH)

image-9.png313x342

Transport Layer Protocol

Notes:

image-10.png405x453

image-11.png405x399

Notes:

SSH Transport Layer Cryptographic Algorithms
image-12.png407x401

Notes:

Client Auth. Methods

Notes:

Connection Protocol

Notes:

Channel Types

Four channel types are recognized in the SSH Connection Protocol specification

Notes:

Port Forwarding

image-13.png444

Notes:

Summary