2022
DOI: 10.1109/access.2022.3166175
|View full text |Cite
|
Sign up to set email alerts
|

HTB: A Very Effective Method to Protect Web Servers Against BREACH Attack to HTTPS

Abstract: BREACH is a side-channel attack to HTTPS that allows an attacker to obtain victims' credentials under certain conditions. An attacker with a privileged position on the network can guess character by character a secret session key just by analyzing the size of the responses returned by the server over HTTPS and encrypted. Heal the Breach (HTB) is the proposed technique to mitigate BREACH attack by randomly changing the size of server responses through a modified gzip library. The attacker needs a precision of o… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
1
0
1

Year Published

2023
2023
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(2 citation statements)
references
References 13 publications
0
1
0
1
Order By: Relevance
“…To conserve time and network traffic, downloader maintain one TCP connection open for each IP address and utilize it repeatedly until the server's entire contents have been downloaded [7]. Web servers compress web pages before transmitting them to the requesting client in order to save network traffic [8]. Downloader use conditional GETs, which are defined in the HTTP protocol.…”
Section: A Reusability Of Tcp Connectionsmentioning
confidence: 99%
“…To conserve time and network traffic, downloader maintain one TCP connection open for each IP address and utilize it repeatedly until the server's entire contents have been downloaded [7]. Web servers compress web pages before transmitting them to the requesting client in order to save network traffic [8]. Downloader use conditional GETs, which are defined in the HTTP protocol.…”
Section: A Reusability Of Tcp Connectionsmentioning
confidence: 99%
“…Un servidor web, por otro lado, es un programa que procesa y responde a varias solicitudes de los navegadores y sirve los recursos solicitados a través del protocolo HTTP o HTTPS (versiones seguras, cifradas y autenticadas de HTTP) (Spacek et al, 2022); (Palacios et al, 2022). Un servidor web simple tiene un esquema de operación muy simple.…”
Section: Introductionunclassified