Web Security
Web Security
Web Security
Essentials
Chapter 5
Fourth Edition
by William Stallings
Lecture slides by Lawrie Brown
Chapter 5
Transport-Level Security
Use your mentality
Wake up to reality
From the song, "I've Got You under My
Skin by Cole Porter
Web Security
Web now widely used by business,
government, individuals
but Internet & Web are vulnerable
have a variety of threats
integrity
confidentiality
denial of service
authentication
SSL Architecture
SSL Architecture
SSL connection
SSL session
message integrity
specific alert
fatal: unexpected message, bad record mac,
decompression failure, handshake failure, illegal
parameter
warning: close notify, no certificate, bad certificate,
unsupported certificate, certificate revoked,
certificate expired, certificate unknown
SSL
Handshake
Protocol
Cryptographic Computations
master secret creation
HTTPS
HTTPS (HTTP over SSL)
encrypts
HTTPS Use
connection initiation
connection closure