TLSsem: A TLS Security-Enhanced Mechanism against MITM Attacks in Public WiFis

Wei Jun Yang, Xiaohong Li, Zhiyong Feng, Jianye Hao · 2017

The widely used TLS protocol is vulnerable to Man-in-the-Middle (MITM) attacks in public WiFis. Such attacks arise since most users are often unable to verify server certificates properly and even worse, the implement of client authentication is typically decoupled from TLS session establishment. These two authentication procedures could be bound cryptographically in the establishment of TLS sessions, and a TLS security-enhanced mechanism (TLSsem) is proposed to detect and defense MITM attacks in public WiFis. TLSsem deals with the TLS mutual authentication through a way that combines pre-binding with certificate validation. Servers take advantage of pre-binding to generate identity credentials for users as pre-shared keys. Afterwards, the mutual authentication between clients and servers is realized in certificate validation by using the identity credentials, and also the forged server certificate is detected on the server side by checking this certificate. In addition, to ensure the reliability of wireless communications in this malicious public WiFis, an TLS shared service based on random port hopping is implemented to reallocate the reliable ports for data transmission against the interception by MITM attackers. We implement a prototype and verify its effectiveness by a thorough set of experiments in the real network environment. Evaluation results show that our mechanism can significantly increase the security of TLS communication in public WiFis without introducing noticeable overhead.

Read the paper · More papers on PaperTik