International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 45 - Number 23 |
Year of Publication: 2012 |
Authors: Pushpendra Kumar Pateriya, Srijith S. Kumar |
10.5120/7092-9816 |
Pushpendra Kumar Pateriya, Srijith S. Kumar . Analysis on Man in the Middle Attack on SSL. International Journal of Computer Applications. 45, 23 ( May 2012), 43-46. DOI=10.5120/7092-9816
Man-In-The-Middle attack is the major attack on SSL. Some of the major attacks on SSL are ARP poisoning and the phishing attack. Phishing is the social engineering attack to steal the credential information from the user using either fake certificates or fake web-pages. Same in the case of ARP Poisoning, where in the attacker act as middle-man in the client-server communication channel. MITM attack makes the users difficult to understand that whether they are connected to original secured connection or not. Since the certificate that is being passed during the connection setup is insecure, attacker can easily modify the information in the certificate and leave the approval of the certificate to the user. Since many users are not well educated about the whereabouts of the forged certificates and their corresponding attacks, they accept the certificates making way for the attackers to implement the attack. To deal with such attacks, two approaches have been proposed: one for the ARP poisoning; and other for phishing attack.