Share

Related Stories

  • The battle of the internet browsers
    Browsers are the hackers’ window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and why user education is one of the primary solutions for increased security
  • Battle of the Internet Browsers
    Browsers are the hacker’s window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and looks at why user education is one of the primary solutions for increased security
  • Comment: It’s Time for Smartphone Security
    As the mobile market grows, so does mobile malware. Don DeBolt, director of threat research at internet security company Total Defense, discusses how IT practitioners and company employees can best stay safe by protecting themselves from mobile hacks, privacy concerns and more in a day and age when mobile malware is on the rise
  • Comment: The SSL Offload Dilemma
    Nathan Pearce of F5 Networks discusses why more organizations are reviewing their security in the wake of recent breaches, how raised security arrangements will inevitably put strain on servers, and the need to take action.
  • Researcher releases malware hub forensics tool for Firefox
    A Websense researcher has released a forensics tool designed to identify malicious web content from within the Firefox browser. Called Fireshark, the plug-in was released on Wednesday at the Black Hat security conference by Stephan Chenette, a principal security researcher at Websense.

Top 5 Stories

News

Breakthrough security Firefox plug-in stops man-in-the-middle attacks

05 September 2008

Researchers at Carnegie Mellon University have released a security plug-in for Firefox 3 that can detect – and block – access to a Web site that has problems with its security certificate.

Instead of drawing on a URL checking database, the Perspectives plug-in verifies the site’s certificate with at least four notary servers on the Internet. These servers verify the certificate and, perhaps more importantly, compare the certificate with what certificate data the site previously offered.

This allows the plug-in to identify those Web sites which have been hacked into and whose pages have been replaced, as well as situations where a hacker has intercepted a users public access WiFi session and is re-routing their URL calls for malicious purposes - a process known as a man-in-the-middle attack.

The problem of site certificates has been complicated in recent times by the fact that, although most site certificates are third-party verified, a growing number now self-certify, making a meaningful analysis of the sites’ veracity almost impossible.

The process of site security certificate validation can be carried out manually by users, using pop-ups and third-party sites, but few Firefox users are capable of such complex checks, which is why the University research team says it developed the Perspectives plug-in.

University researchers say that their plug-in will automatically override the Firefox 3 security error page without scaring the user if the site appears legitimate.

If Perspectives receives anything less than a majority opinion from the polled notary servers, the software shows a warning page that reads: "Suspected attack: Perspectives was unable to verify the security of your connection to this Web site."

http://www.cs.cmu.edu/~perspectives/index.html
This article is featured in:
Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.