Security Analysis and Deployment Measurement of Transport Layer Security Protocol
الباحث الأول:
Marwah Yaseen
الباحثين الآخرين:
Mohammed Kamel,
Peter Ligeti
المجلة:
Recent Innovations in Computing
تاريخ النشر:
None
مختصر البحث:
The Transport Layer Security (TLS) protocol is intended to provide secure communication over insecure computer networks, such as the Internet [3]. Many studies covered the verification of security protocols. The motivation comes from the fact that m…
The Transport Layer Security (TLS) protocol is intended to provide secure communication over insecure computer networks, such as the Internet [3]. Many studies covered the verification of security protocols. The motivation comes from the fact that many security issues may not be detected during the testing phases, as some of the issues happened in the presence of a malicious adversary only [4]. This paper focuses on verifying the security of Transport Layer Security (TLS) protocol using the ProVerif verification tool, a fully automatic tool for formal analysis of security protocols using Horn clauses. We intensively studied the TLS protocol and outlined the security issues on its various versions and how these issues have been addressed in the later releases. This analysis will give the ability to propose an abstract model of it to formalize the achieved understanding of TLS. Then, the ProVerif tool will be used to analyze and verify the security and privacy properties of the TLS protocol. Finally, based on the analysis some modifications to the TLS protocol description will be presented and analyzed, and then compared with the original protocol. In addition to that, we monitored the use of the different versions of TLS by scanning a large range of popular domains and analyzing the adopted TLS versions. We showed that TLS 1.3 is deployed speedily and with no security concerns, compared to TLS 1.2 where the adoption took more than five years. Our analysis shows that 52% of the scanned domains support TLS 1.3. Furthermore, we categorized the data according to the main services categories, such as the educational domains, informative domains, general domains and so on, to analyze the distribution of TLS versions adoption over these categories. We showed that the “.org” domains have a high TLS 1.3 deployment rate and the “.edu” domains have a low TLS 1.3 deployment rate among the scanned domains.