Usage of RC4 Cipher in SSL Configurations in Web Portals of Sri Lankan Banking/Non-Banking Financial Institutes and Awareness Levels of Relevant Staff About It

T.D.B Weerasinghe, Chamara Disanayake · 2018

Internet security is based on Secure Socket Layer (SSL) or its successor Transport Layer Security (TLS). In order to secure online transactions, the banking and non-banking financial organizations widely use the SSL/TLS protocols in their web portals. In SSL, a lot of cipher suits are used as encryption algorithms. RC4 is the most commonly used stream cipher, although it is regarded as a weak cipher. By the time of the research, it was used in SSL as an encryption algorithm and even now RC4 can be used in SSL configurations. The usage of SSL is the most renowned security mechanism for maintaining a secure link between a web server and a browser [1]. Nonetheless the stream cipher RC4 is found to be vulnerable to various attacks [2]. The main objective of this study is to find-out the usage of RC4 stream cipher in online web portals of Sri Lankan Banking and Non-Banking Financial Sector, as well as the awareness level of the Network Security Administrating staff of some of the selected banks which are geographically based in Sri Lanka, regarding the usage of RC4 in SSL.

Read the paper · More papers on PaperTik