Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @inproceedings{bhargavan2014triple,
- title={Triple handshakes and cookie cutters: Breaking and fixing authentication over {TLS}},
- author={Bhargavan, Karthikeyan and Lavaud, Antoine Delignat and Fournet, C{\'e}dric and Pironti, Alfredo and Strub, Pierre Yves},
- booktitle={IEEE Symposium on Security and Privacy (SP)},
- year={2014},
- pages={98--113},
- organization={IEEE}
- }
- @inproceedings{fahl2012eve,
- title={Why {Eve} and {Mallory} Love {Android}: An Analysis of {Android} {SSL} (in) Security},
- author={Fahl, Sascha and Harbach, Marian and Muders, Thomas and Baumg{\"a}rtner, Lars and Freisleben, Bernd and Smith, Matthew},
- booktitle={ACM Conference on Computer and Communications Security (CCS)},
- pages={50--61},
- year={2012},
- organization={ACM}
- }
- @inproceedings{fahl2013rethinking,
- title={Rethinking {SSL} development in an appified world},
- author={Fahl, Sascha and Harbach, Marian and Perl, Henning and Koetter, Markus and Smith, Matthew},
- booktitle={ACM Conference on Computer and Communications Security (CCS)},
- year={2013},
- pages={49--60},
- organization={ACM}
- }
- @inproceedings{georgiev2012most,
- title={The most dangerous code in the world: validating {SSL} certificates in non-browser software},
- author={Georgiev, Martin and Iyengar, Subodh and Jana, Suman and Anubhai, Rishita and Boneh, Dan and Shmatikov, Vitaly},
- booktitle={ACM Conference on Computer and Communications Security (CCS)},
- year={2012},
- pages={38--49},
- organization={ACM}
- }
- @inproceedings{he2015vetting,
- title={Vetting {SSL} usage in applications with {SSLint}},
- author={He, Boyuan and Rastogi, Vaibhav and Cao, Yinzhi and Chen, Yan and Venkatakrishnan, VN and Yang, Runqing and Zhang, Zhenrui},
- booktitle={IEEE Symposium on Security and Privacy (SP)},
- year={2015},
- pages={519--534},
- organization={IEEE}
- }
- @InCollection{ amour2015improving,
- title = {Improving Application Security through {TLS}-Library
- Redesign},
- author = {Amour, Leo St and Petullo, W Michael},
- booktitle = {Security, Privacy, and Applied Cryptography Engineering (SPACE)},
- pages = {75--94},
- year = {2015},
- publisher = {Springer}
- }
- @InCollection{ conti2013mithys,
- title = {{MITHYS}: Mind the hand you shake-protecting mobile
- devices from {SSL} usage vulnerabilities},
- author = {Conti, Mauro and Dragoni, Nicola and Gottardo,
- Sebastiano},
- booktitle = {Security and Trust Management},
- pages = {65--81},
- year = {2013},
- publisher = {Springer}
- }
- @InProceedings{ bates2014securing,
- title = {Securing {SSL} certificate verification through dynamic
- linking},
- author = {Bates, Adam and Pletcher, Joe and Nichols, Tyler and
- Hollembaek, Braden and Tian, Dave and Butler, Kevin RB and
- Alkhelaifi, Abdulrahman},
- booktitle = {ACM Conference on Computer and Communications Security (CCS)},
- pages = {394--405},
- year = {2014}
- }
- @InProceedings{Sounthiraraj14smv-hunter:large,
- author = {David Sounthiraraj and Justin Sahs and Garret Greenwood and Zhiqiang Lin and Latifur Khan},
- title = {Smv-hunter: Large scale, automated detection of {SSL/TLS} man-in-the-middle vulnerabilities in {Android} apps},
- booktitle = {Network and Distributed System Security Symposium (NDSS)},
- year = {2014}
- }
- @InProceedings{oneill2017trustbase,
- title = {TrustBase: An Architecture to Repair and Strengthen Certificate-based Authentication},
- author = {O'Neill, Mark and Heidbrink, Scott and Ruoti, Scott and Whitehead, Jordan and Bunker, Dan and Dickinson, Luke and Hendershot, Travis and Reynolds, Joshua and Seamons, Kent and Zappala, Daniel},
- booktitle = {USENIX Security Symposium},
- year = {2017}
- }
- @InProceedings{ brubaker2014using,
- title = {Using Frankencerts for Automated Adversarial Testing of Certificate Validation in {SSL/TLS} Implementations},
- author = {Brubaker, Chad and Jana, Suman and Ray, Baishakhi and Khurshid, Sarfraz and Shmatikov, Vitaly},
- booktitle = {IEEE Symposium on Security and Privacy (SP)},
- pages={114--129},
- year = {2014},
- organization={IEEE}
- }
- @InProceedings{ onwuzurike2015danger,
- title = {Danger is my middle name: experimenting with {SSL} vulnerabilities in {Android} apps},
- author = {Onwuzurike, Lucky and De Cristofaro, Emiliano},
- booktitle = {ACM Conference on Security \& Privacy in Wireless and Mobile Networks (WiSec)},
- year = {2015},
- pages = {1--6},
- organization = {ACM}
- }
Advertisement
Add Comment
Please, Sign In to add comment