Related Experiment Videos
A monitoring/auditing mechanism for SSL/TLS secured service sessions in Health Care Applications
C D Kavadias1, K A Koutsopoulos, M P Vlachos
1National Technical University of Athens (NTUA); Department of Electrical & Computer Engineering, 9, Heroon Polytechniou Str., 157 73, Zographou, Athens, Greece. cavadias.kkoutso@telecom.ntua.gr
Abstract:
This paper analyzes the SSL/TLS procedures and defines the functionality of a monitoring/auditing entity running in parallel with the protocol, which is decoding, checking the certificate and permitting session establishment based on the decoded certificate information, the network addresses of the endpoints and a predefined access list. Finally, this paper discusses how such a facility can be used for detection impersonation attempts in Health Care applications and provides case studies to show the effectiveness and applicability of the proposed method.