Detecting Unauthorized Modification of HTTP Communication with Steganography
Tomáš Koutný · 2010
HTTP does not secure its requests and responses. Using Man-in-the-Middle attack, it is possible to alter the HTTP communication, while it still would look authentic. This can be a problem, if you download data such as PGP key, TOR client, access banking services on-line, or when there is an interest to filter what you can read on the Internet. It should be noted that under particular circumstances, it is possible to attack HTTPS secured communication successfully. This paper proposes a steganography scheme that can be used to detect unauthorized modifications of HTTP communication.