Phishing対策のためのMutualアクセス認証 〜 MutualTestFoxの公開について 〜

Similar documents
第2回_416.ppt

Flash Player ローカル設定マネージャー

untitled

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

ict8.key


Microsoft PowerPoint - 情報システム pptx

Google Apps Google Apps for Work Education Government Drive for Work Google Apps Unlimited


内閣官房情報セキュリティセンター(NISC)

pg. 2

untitled

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

正しいフィッシング対策について

untitled

Cisco Configuration Professional(CCP)Express 3.3 による Cisco 841M J シリーズ初期設定ガイド

Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved. 3 Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved.

25 About what prevent spoofing of misusing a session information

InterSafe Personal_v2.3 ユーザーズガイド_初版

untitled

TLS _final

Google Apps / Gmail

IP S ( :H ) ( ) ( :H22 4

untitled

shio_ PDF

untitled

/02/ /09/ /05/ /02/ CA /11/09 OCSP SubjectAltName /12/02 SECOM Passport for Web SR

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

5-5_arai_JPNICSecSemi_XssCsrf_CM_ PDF

untitled

H indd

Web 1 1 Web 1 java Web 1 1 2

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

真のフィッシング対策について

DNS DNS...

インターネット利用ソリューション

金融機関のセキュリティ対策の動向について


1 Web 1W e b Q Pay-easy 2 31 Web :00 315:00 15:00 315:00 Q 515:00 Q 9 30 Q :00 6:00 21:00 6:

atama.dvi

manual.dvi

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

LAN

2

untitled

はじめに

untitled

untitled

BIG‑IP Access Policy Manager | F5 Datasheet

Kaspersky Internet Security 2010


YMS-VPN1_User_Manual

Kaspersky Anti-Virus 2010

スライド 1

sp c-final

Taro jtd


NO

PowerPoint プレゼンテーション

IT講習会

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

/07/ /10/12 I

(O) (N) (V) (N) kuins-pptp (N) 2

P TCP IP ISDN ISDN TA DSU DSU

Cisco Configuration Professional(CCP)Express による Cisco 841M J シリーズ初期設定ガイド

untitled

untitled

裏技情報ファイル3

Macintosh HD:Users:ks91:Documents:lect:nm2002s:nm2002s03.dvi

<Documents Title Here>

_KAIT.pptx

Oracle Application Server 10g(9

<Documents Title Here>

改善活動が加速する 社内ネットワーク ~SPI車座集会と社内SNS ~

宅建練馬表478号1_4ol [更新済み].eps


Web Web Web

HTTP2 HTTP2 http2fuzz ATS Firefox NodeJS


橡ファミリー企業の分析020806


<Documents Title Here>

untitled

rzat10pdf.ps

Microsoft Windows, Windows CE, Microsoft Corporation Citrix ICA Citrix Presentation Server Citrix Systems, Inc IBM IBM Corporation

07_経営論集2010 小松先生.indd

untitled

SAML

untitled

動物の適正譲渡における飼い主教育

Orion ネットワークコンフィグレーションマネージャ紹介


操作1 <設問作成>

Web STEPS Web Web Form Cookie HTTP STEPS Web

Lync Server 2010 Lync Server Topology Builder BIG-IP LTM Topology Builder IP Lync 2010 BIG IP BIG-IP VE Virtual Edition BIG-IP SSL/TLS BIG-IP Edge Web

/

PowerPoint プレゼンテーション

3 no.

rzammpdf.ps

/

Transcription:

Mozilla Party 9.0 2008 5 31 MutualTestFox Phishing Mutual Phishing MutualPhishing WebMutual BasicDigest HTML Form 2

3 4

5 4 22 MutualTestFox 3.0!5+draft02.0 (r718) mod_auth_mutual (r718) 5 8 (r736) J(pi) draft01 ISO 11770-4 FAQ 5 29 Firefox 3.0RC1 (r791) r736 6

Yahoo! JAPAN 2006 1 Phishing HTTP Mutual MutualTestFoxmod_auth_mutual IETF 7 Web Internet Draft (IETF) ( ) RFC 2006 2007 2008 2009 2010 2011 8

Phishing Firefox phishing 9! 10

11 12

PayPalphishing PayPal phishing spam PayPalspam PayPal phishing!! 13 14

15 16

spam 17 18

19 &'()! *+#$%! 1002/01 1003/01 1002,-.? 1003,-.?!"#$%! 20

Citibank Phish Spoofs 2-Factor Authentication (2006/7/10) http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs_2factor_1.html Man-in-the-middle attack on Citibank users concerns experts (2006/7/14) http://www.scmagazine.com/us/news/article/569881/man-in-the-middle-attack-citibank-usersconcerns-experts/ Bank Systems & Technology: Phishers Beat Citi's Two-Factor Authentication (2006/7/18) http://www.banktech.com/rdelivery/showarticle.jhtml?articleid=190500614 FST US Article: Phishing and forward looking financial institutions http://www.usfst.com/pastissue/article.asp?art=268947&issue=183 Man-in-the-middle attacks Citi authentication system (2006/12/7) http://www.finextra.com/fullstory.asp?id=15570 RSA Alert: New Universal Man-in-the-Middle Phishing Kit Discovered (2007/1/10) http://www.rsasecurity.com/press_release.asp?doc_id=7667 21 Location Bar 22

23 VPN phishing Web TLS(SSL) phishing EV SSL 24

Mutual VPN Web 25 26

Mutual Mutual Mutual 27! 28

29 URL TLS 30

Chrome IE 6 SP1 Firefox 3 Location Bar 31 Basic Digest Mutual 32

HTTP RFC 2617, HTTP Authentication: Basic and Digest Access Authentication 1999 Basic Access Authentication Basic Digest Access Authentication (Digest RFC???? 20?? Mutual Access Authentication (Mutual 33 TLS TLS DNS spoofing TLS http:// Mutual 34

35 Digest Digest PAKE PAKE TLS-SRP TLS-SRP 36

PAKE Mutual 37 NIST SP 800-63 Appendix A 40 62 100 16 80100 PAKE 38

!"#$%&! request '()! (*+,(-) *+,(-! 401 Auth req ed 23sa wa Req-a1 (wa) 401-B1 (wb) wb (wa)./0(1 J(!) 23 sb (wb) z oa Req-A3 (oa) (oa) z oa ob = (ob) ('()./) 200-B4 (ob) ob = (!"#$%&./) (4567) 39 iso-11770-4-dl2048 2048bit 256bit (H = SHA256) mod q, mod r u, p, h " " = H(algorithm h realm u p) DB J(") J(") = g" J : 40

TLS TLS TLS-SRP (RFC 5054) Web IMAP over TLS-SRP IETF Informational TLS 41 HTML Form XSS cookie Session Fixation HTTP CSRF (Cross-Site Request Forgery) 42

Basic UI Mutual 43 SSO auth-domain *.example.com SSO Liberty OpenID 44

DB Mutual DB 45 Firefox RFC IETF HTTPWeb Mutual MicrosoftInternet Explorer Yahoo! 6 46