28.02.2014 Views

Internet & Intranet Security Management - Risks & Solutions

Internet & Intranet Security Management - Risks & Solutions

Internet & Intranet Security Management - Risks & Solutions

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

has not been altered during transmission.<br />

• IP Encapsulated <strong>Security</strong> Payload (ESP). ESP provides data confidentiality. This means, only<br />

legitimate recipients of an IP packet (hosts) are able to read its content.<br />

Secure Sockets Layer<br />

The Secure Sockets Layer protocol (SSL) (Bhimani, 1996) is a protocol layer developed by Netscape<br />

Communications Corporation which may be placed between a reliable connection-oriented network<br />

layer protocol (e.g. TCP) and the application protocol layer (e.g. HTTP). SSL protects the<br />

communication stream between client and server by providing mutual authentication, integrity and<br />

privacy. One common use of SSL is to secure HTTP communication between a Web client and a Web<br />

server. In this case, SSL connections are initiated from a Web client through the use of special URL<br />

prefix. For example,<br />

Table 9.<br />

SSL runs above TCP/IP and below application protocols (e.g. HTTP)<br />

the prefix ''https:" is used to indicate an HTTP connection over SSL (see Figure 9).<br />

SSL provides a range of security services for client/server sessions. The SSL protocol includes two<br />

sub-protocols: the SSL record protocol and the SSL handshake protocol. The SSL record protocol is<br />

layered on top of some reliable transport protocol (e.g., TCP) and deals with data fragmentation,<br />

compression, authentication, and encryption/decryption. The SSL record protocol provides:<br />

• Integrity. Data items transferred in the session are protected against modification with an integrity<br />

check-value.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!