2017 IEEE Symposium on Security and Privacy (SP) 2017
DOI: 10.1109/sp.2017.46
|View full text |Cite
|
Sign up to set email alerts
|

HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL/TLS Implementations

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
26
0

Year Published

2017
2017
2023
2023

Publication Types

Select...
5
3
2

Relationship

0
10

Authors

Journals

citations
Cited by 59 publications
(26 citation statements)
references
References 16 publications
0
26
0
Order By: Relevance
“…Sivakorn et al [52] proposed a black-box hostname verification testing framework for TLS libraries and applications. They evaluated the hostnames accepted by seven TLS libraries and applications and found eight violations, including: invalid hostname characters, incorrect null characters parsing, and incorrect wildcard parsing.…”
Section: Related Workmentioning
confidence: 99%
“…Sivakorn et al [52] proposed a black-box hostname verification testing framework for TLS libraries and applications. They evaluated the hostnames accepted by seven TLS libraries and applications and found eight violations, including: invalid hostname characters, incorrect null characters parsing, and incorrect wildcard parsing.…”
Section: Related Workmentioning
confidence: 99%
“…Analysis assuming known protocol format: Other approaches [2,27,36] perform protocol and device analysis assuming protocol format is known. For instance, Alembic [27] tackled the problem of inferring the stateful model in a form of a finite state machine (FSM) of network functions (e.g., firewalls, NAT).…”
Section: Prior Work and Limitationsmentioning
confidence: 99%
“…Differential fuzzing has been successfully applied before for finding bugs and vulnerabilities in a variety of applications, such as LF and XZ parsers, PDF viewers, SSL/TLS libraries, and C compilers [36], [38], [41]. However, to the best of our knowledge, we are the first to explore differential fuzzing for side-channel analysis.…”
Section: Introductionmentioning
confidence: 99%