Timing Analysis of SSL/TLS Man in the Middle Attacks
This addresses security threats for e-commerce and online communications, but appears incremental as it builds on existing timing analysis methods.
The paper tackled the problem of detecting man-in-the-middle attacks on SSL/TLS by analyzing timing differences between standard sessions and attacks, but no concrete results or numbers are provided in the abstract.
Man in the middle attacks are a significant threat to modern e-commerce and online communications, even when such transactions are protected by TLS. We intend to show that it is possible to detect man-in-the-middle attacks on SSL and TLS by detecting timing differences between a standard SSL session and an attack we created.