Improved SSL/TLS Man-in-the-middle attack detection technique using timing analysis and other behavioral anomalies
Samuel Folarin
Abstract
Open-access reader
Samuel Folarin
Abstract
Open-access reader
Even with the necessary protection that the TLS protocol is assumed to provide, data communications and financial transactions carried out online have been noted to be at great risk due to the impending danger of Man-in-the-middle attacks. This research was conducted to confirm the possibility of mitigating the continuous threat that attacks such as the man-in-the-middle constitute to the SSL and TLS key exchange by analyzing differences in time and other possible behavioral anomalies between a simulated attack and a standard SSL session through the use of machine learning. The results gotten in this research have been used to demonstrate the successful implementation of an improved SSL/TLS MiTM detection system.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Even with the necessary protection that the TLS protocol is assumed to provide, data communications and financial transactions carried out online have been noted to be at great risk due to the impending danger of Man-in-the-middle attacks. This research was conducted to confirm the possibility of mitigating the continuous threat that attacks such as the man-in-the-middle constitute to the SSL and TLS key exchange by analyzing differences in time and other possible behavioral anomalies between a simulated attack and a standard SSL session through the use of machine learning. The results gotten in this research have been used to demonstrate the successful implementation of an improved SSL/TLS MiTM detection system.
Key concepts: Man-in-the-middle attack, Transport Layer Security, Computer security, Computer science, Key (lock), Session (web analytics), Protocol (science), World Wide Web