The main goal of the thesis is the investigation of problems in security checks of encrypted web traffic. Both web and internet security are endangered in many ways.
Most of the public network connections today are encrypted on the transport layer. In the first part, I therefore provide the necessary basics of important cryptographic protocols and their role on the internet. I also specify the importance of certificates and the course of the handshake itself.
The percentage of encrypted traffic is increasing day by day thereby increasing the online security risks. Encrypted traffic must be securely supervised and checked. Visibility in encrypted traffic is crucial for data protection In the event that encrypted traffic is not reviewed, there is a high probability that we will not detect certain attacks, and our organization will be vulnerable to violations.
Chapter four of the assignment examines a general overview of security at the encrypted traffic level. The most common vulnerabilities and types of attacks on the transport layer are specified. Of course it is almost impossible to present all of them, since there are over 180 of them in the OpenSSL cryptographic library alone [1].
In the continuation of the assignment, I discuss and describe problems at the level of non-encrypted connections. In the main part of the assignment I also provide an analysis of the security solutions provided by the software from the manufacturer F5 Networks for encrypted traffic.
SSL provides security, but brings with it challenges at the level of ensuring effective data protection, which is why that is the focus of the next chapter. Given the current trends, soon there will only be encrypted traffic. In the continuation, I provide a solution with the help of an application from the leading provider of SSL technology solutions, manufactured by F5 Networks. The practical solution is carried out by means of insight into encrypted traffic and orchestration of said traffic.
|