{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,12]],"date-time":"2026-02-12T16:47:54Z","timestamp":1770914874694,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2007,10,24]],"date-time":"2007-10-24T00:00:00Z","timestamp":1193184000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2007,10,24]]},"DOI":"10.1145\/1298306.1298318","type":"proceedings-article","created":{"date-parts":[[2007,11,15]],"date-time":"2007-11-15T14:30:20Z","timestamp":1195137020000},"page":"83-92","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":45,"title":["Cryptographic strength of ssl\/tls servers"],"prefix":"10.1145","author":[{"given":"Homin K.","family":"Lee","sequence":"first","affiliation":[{"name":"Columbia University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tal","family":"Malkin","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erich","family":"Nahum","sequence":"additional","affiliation":[{"name":"IBM T. J. Watson Research Ctr., Hawthorne, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2007,10,24]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Alexa Web Search - Top 500. http:\/\/www.alexa.com\/site\/ds\/top_500.  Alexa Web Search - Top 500. http:\/\/www.alexa.com\/site\/ds\/top_500."},{"key":"e_1_3_2_1_2_1","unstructured":"IRCache. http:\/\/www.ircache.net.  IRCache. http:\/\/www.ircache.net."},{"key":"e_1_3_2_1_3_1","unstructured":"Nmap. http:\/\/www.insecure.org\/nmap\/.  Nmap. http:\/\/www.insecure.org\/nmap\/."},{"key":"e_1_3_2_1_4_1","unstructured":"The OpenSSL project. http:\/\/www.openssl.org.  The OpenSSL project. http:\/\/www.openssl.org."},{"key":"e_1_3_2_1_5_1","unstructured":"Web100. http:\/\/www.web100.com.  Web100. http:\/\/www.web100.com."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.1999.751458"},{"key":"e_1_3_2_1_8_1","series-title":"Lecture Notes in Computer Science","first-page":"534","volume-title":"Advances in Cryptology --CRYPTO","author":"Bellare Mihir","year":"1996","unstructured":"Mihir Bellare , Ran Canetti , and Hugo Krawczyk . Keying hash functions for message authentication . In N. Koblitz, editor, Advances in Cryptology --CRYPTO 1996 , volume 1109 of Lecture Notes in Computer Science , pages 534 -- 545 . Springer-Verlag , 1996. Mihir Bellare, Ran Canetti, and Hugo Krawczyk. Keying hash functions for message authentication. In N. Koblitz, editor, Advances in Cryptology --CRYPTO 1996, volume 1109 of Lecture Notes in Computer Science, pages 534--545. Springer-Verlag, 1996."},{"key":"e_1_3_2_1_9_1","volume-title":"The 12th USENIX Security Symposium","author":"Boneh Dan","year":"2003","unstructured":"Dan Boneh and David Brumley . Remote timing attacks are practical . In The 12th USENIX Security Symposium , August 2003 . Dan Boneh and David Brumley. Remote timing attacks are practical. In The 12th USENIX Security Symposium, August 2003."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1124153.1124155"},{"key":"e_1_3_2_1_11_1","volume-title":"February","author":"NESSIE Consortium","year":"2003","unstructured":"NESSIE Consortium . Portfolio of recommended cryptographic primitives. Internet draft , February 2003 . http:\/\/www.cryptonessie.org\/. NESSIE Consortium. Portfolio of recommended cryptographic primitives. Internet draft, February 2003. http:\/\/www.cryptonessie.org\/."},{"key":"e_1_3_2_1_12_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1007\/3-540-36178-2_17","volume-title":"Advances in Cryptology - ASIACRYPT","author":"Courtois Nicolas","year":"2002","unstructured":"Nicolas Courtois and Josef Pieprzyk . Cryptanalysis of block ciphers with overdefined systems of equations . In Yuliang Zheng, editor, Advances in Cryptology - ASIACRYPT 2002 , volume 2501 of Lecture Notes in Computer Science , pages 267 -- 287 . Springer-Verlag , 2002. Nicolas Courtois and Josef Pieprzyk. Cryptanalysis of block ciphers with overdefined systems of equations. In Yuliang Zheng, editor, Advances in Cryptology - ASIACRYPT 2002, volume 2501 of Lecture Notes in Computer Science, pages 267--287. Springer-Verlag, 2002."},{"key":"e_1_3_2_1_13_1","series-title":"Lecture Notes in Computer Science","first-page":"293","volume-title":"Advances in Cryptology -- EUROCRYPT","author":"den Boer B.","year":"1993","unstructured":"B. den Boer and A. Bosselaers . Collisions for the compression function of MD5 . In Tor Helleseth, editor, Advances in Cryptology -- EUROCRYPT 1993 , volume 470 of Lecture Notes in Computer Science , pages 293 -- 304 . Springer-Verlag , 1994. B. den Boer and A. Bosselaers. Collisions for the compression function of MD5. In Tor Helleseth, editor, Advances in Cryptology -- EUROCRYPT 1993, volume 470 of Lecture Notes in Computer Science, pages 293--304. Springer-Verlag, 1994."},{"key":"e_1_3_2_1_14_1","volume-title":"January","author":"Dierks T.","year":"1999","unstructured":"T. Dierks and C. Allen . The TLS protocol, version 1.0 , January 1999 . RFC- 2246. T. Dierks and C. Allen. The TLS protocol, version 1.0, January 1999. RFC-2246."},{"key":"e_1_3_2_1_15_1","volume-title":"June","author":"Dierks Tim","year":"2005","unstructured":"Tim Dierks and Eric Rescorla . The TLS protocol, version 1.1 , June 2005 . Internet Draft , http:\/\/www.ietf.org\/internet-drafts\/draft-ietf-tls-rfc2246-bis-13.txt, expires December 2005. Tim Dierks and Eric Rescorla. The TLS protocol, version 1.1, June 2005. Internet Draft, http:\/\/www.ietf.org\/internet-drafts\/draft-ietf-tls-rfc2246-bis-13.txt, expires December 2005."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/647931.740714"},{"key":"e_1_3_2_1_17_1","volume-title":"The status of MD5 after a recent attack. CryptoBytes, 2(2)","author":"Dobbertin Hans","year":"1996","unstructured":"Hans Dobbertin . The status of MD5 after a recent attack. CryptoBytes, 2(2) , 1996 . Hans Dobbertin. The status of MD5 after a recent attack. CryptoBytes, 2(2), 1996."},{"key":"e_1_3_2_1_18_1","volume-title":"Practical Cryptography","author":"Ferguson N.","year":"2003","unstructured":"N. Ferguson and B. Schneier . Practical Cryptography . Wiley Publishing, Inc. , 2003 . N. Ferguson and B. Schneier. Practical Cryptography. Wiley Publishing, Inc., 2003."},{"key":"e_1_3_2_1_19_1","series-title":"Lecture Notes in Computer Science","first-page":"1","volume-title":"Selected Areas in Cryptography","author":"Fluhrer Scott","year":"2001","unstructured":"Scott Fluhrer , Itsik Mantin , and Adi Shamir . Weaknesses in the key scheduling algorithm of RC4 . In Selected Areas in Cryptography , volume 2259 of Lecture Notes in Computer Science , pages 1 -- 24 , 2001 . Scott Fluhrer, Itsik Mantin, and Adi Shamir. Weaknesses in the key scheduling algorithm of RC4. In Selected Areas in Cryptography, volume 2259 of Lecture Notes in Computer Science, pages 1--24, 2001."},{"key":"e_1_3_2_1_20_1","volume-title":"Netscape Communications","author":"Freier Alan O.","year":"1996","unstructured":"Alan O. Freier , Philip Karlton , and Paul C. Kocher . The SSL protocol version 3.0. Internet draft , Netscape Communications , November 1996 . http:\/\/wp.netscape.com\/eng\/ssl3\/ssl-toc.html. Alan O. Freier, Philip Karlton, and Paul C. Kocher. The SSL protocol version 3.0. Internet draft, Netscape Communications, November 1996. http:\/\/wp.netscape.com\/eng\/ssl3\/ssl-toc.html."},{"key":"e_1_3_2_1_21_1","unstructured":"Eu-Jin Goh. SSL sniffer. http:\/\/crypto.stanford.edu\/~eujin\/sslsniffer\/index.html.  Eu-Jin Goh. SSL sniffer. http:\/\/crypto.stanford.edu\/~eujin\/sslsniffer\/index.html."},{"key":"e_1_3_2_1_22_1","volume-title":"Netscape Communications","author":"Hickman Kipp E. B.","year":"1995","unstructured":"Kipp E. B. Hickman . The SSL protocol. Internet draft , Netscape Communications , February 1995 . http:\/\/wp.netscape.com\/eng\/security\/SSL_2.html. Kipp E. B. Hickman. The SSL protocol. Internet draft, Netscape Communications, February 1995. http:\/\/wp.netscape.com\/eng\/security\/SSL_2.html."},{"key":"e_1_3_2_1_23_1","volume-title":"RSA Laboratories","author":"Kaliski Burt","year":"2003","unstructured":"Burt Kaliski . TWIRL and RSA key size. Internet draft , RSA Laboratories , May 2003 . http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2004. Burt Kaliski. TWIRL and RSA key size. Internet draft, RSA Laboratories, May 2003. http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2004."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/647933.740749"},{"key":"e_1_3_2_1_26_1","first-page":"69","volume-title":"Proceedings of the ACM SIGMETRICS Workshop on Internet Server Performance (WISP)","author":"Mosberger D.","year":"1998","unstructured":"D. Mosberger and T. Jin . httperf -- a tool for measuring Webserver performance . In Proceedings of the ACM SIGMETRICS Workshop on Internet Server Performance (WISP) , pages 69 -- 67 , Madison, WI , June 1998 . D. Mosberger and T. Jin. httperf -- a tool for measuring Webserver performance. In Proceedings of the ACM SIGMETRICS Workshop on Internet Server Performance (WISP), pages 69--67, Madison, WI, June 1998."},{"key":"e_1_3_2_1_27_1","volume-title":"USENIX Security Symposium 2001","author":"Murray Eric","year":"2001","unstructured":"Eric Murray . Changes in deployment of cryptography. Invited talk , USENIX Security Symposium 2001 . http:\/\/www.usenix.org\/events\/sec01\/murray\/index.htm, July 2001 . Eric Murray. Changes in deployment of cryptography. Invited talk, USENIX Security Symposium 2001. http:\/\/www.usenix.org\/events\/sec01\/murray\/index.htm,July 2001."},{"key":"e_1_3_2_1_28_1","unstructured":"Netcraft News. Vulnerable versions of OpenSSL apparently still widely deployed on commerce sites. http:\/\/news.netcraft.com\/archives\/2003\/11\/03\/vulnerable_versions_of_openssl_apparently_still_widely_deployed_on_commerce_sites.html.  Netcraft News. Vulnerable versions of OpenSSL apparently still widely deployed on commerce sites. http:\/\/news.netcraft.com\/archives\/2003\/11\/03\/vulnerable_versions_of_openssl_apparently_still_widely_deployed_on_commerce_sites.html."},{"key":"e_1_3_2_1_29_1","unstructured":"NIST. Data encryption standard DES December 1993. http:\/\/www.itl.nist.gov\/fipspubs\/fip46-2.htm.  NIST. Data encryption standard DES December 1993. http:\/\/www.itl.nist.gov\/fipspubs\/fip46-2.htm."},{"key":"e_1_3_2_1_30_1","volume-title":"federal information processing standards publication","author":"NIST.","year":"1995","unstructured":"NIST. Secure hash standard , federal information processing standards publication 180-1, April 1995 . http:\/\/www.itl.nist.gov\/fipspubs\/fip180-1.htm. NIST. Secure hash standard, federal information processing standards publication 180-1, April 1995. http:\/\/www.itl.nist.gov\/fipspubs\/fip180-1.htm."},{"key":"e_1_3_2_1_31_1","volume-title":"federal information processing standards publication","author":"NIST.","year":"2001","unstructured":"NIST. Advanced encryption standard (AES) , federal information processing standards publication 197, November 2001 . http:\/\/www.csrc.nist.gov\/publications\/fips\/fips197\/fips-197.pdf. NIST. Advanced encryption standard (AES), federal information processing standards publication 197, November 2001. http:\/\/www.csrc.nist.gov\/publications\/fips\/fips197\/fips-197.pdf."},{"key":"e_1_3_2_1_32_1","volume-title":"January","author":"NIST.","year":"2003","unstructured":"NIST. Special publication 800-57 : Recommendation for key management. part 1: General guideline , January 2003 . http:\/\/csrc.nist.gov\/CryptoToolkit\/kms\/guideline-1-Jan03.pdf. NIST. Special publication 800-57: Recommendation for key management. part 1: General guideline, January 2003. http:\/\/csrc.nist.gov\/CryptoToolkit\/kms\/guideline-1-Jan03.pdf."},{"key":"e_1_3_2_1_33_1","unstructured":"NIST. Announcing proposed withdrawal of federal information processing standard (FIPS) for the data encryption standard (DES) and request for comments July 2004. http:\/\/edocket.access.gpo.gov\/2004\/04-16894.htm.  NIST. Announcing proposed withdrawal of federal information processing standard (FIPS) for the data encryption standard (DES) and request for comments July 2004. http:\/\/edocket.access.gpo.gov\/2004\/04-16894.htm."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/383059.383083"},{"key":"e_1_3_2_1_35_1","first-page":"25","volume-title":"USENIX Large Installation System Administration Conference(LISA)","author":"Provos Niels","year":"2001","unstructured":"Niels Provos and Peter Honeyman . ScanSSH : Scanning the Internet for SSH servers . In USENIX Large Installation System Administration Conference(LISA) , pages 25 -- 30 , 2001 . Niels Provos and Peter Honeyman. ScanSSH: Scanning the Internet for SSH servers. In USENIX Large Installation System Administration Conference(LISA), pages 25--30, 2001."},{"key":"e_1_3_2_1_36_1","volume-title":"Addison Wesley","author":"Rescorla Eric","year":"2000","unstructured":"Eric Rescorla . SSL and TLS . Addison Wesley , 2000 . Eric Rescorla. SSL and TLS. Addison Wesley, 2000."},{"key":"e_1_3_2_1_37_1","first-page":"75","volume-title":"Proceedings of the 12th USENIX Security Symposium","author":"Rescorla Eric","year":"2003","unstructured":"Eric Rescorla . Security holes... who cares ? In Proceedings of the 12th USENIX Security Symposium , pages 75 -- 90 , August 2003 . Eric Rescorla. Security holes... who cares? In Proceedings of the 12th USENIX Security Symposium, pages 75--90, August 2003."},{"key":"e_1_3_2_1_38_1","volume-title":"April","author":"Rivest Ron","year":"1992","unstructured":"Ron Rivest . The MD5 message digest algorithm , April 1992 . RFC- 1321. Ron Rivest. The MD5 message digest algorithm, April 1992. RFC-1321."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"e_1_3_2_1_40_1","unstructured":"RSA Laboratories. How large a key should be used inthe RSA cryptosystem? Internet draft RSA Crypto FAQ. http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2218.  RSA Laboratories. How large a key should be used inthe RSA cryptosystem? Internet draft RSA Crypto FAQ. http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2218."},{"key":"e_1_3_2_1_41_1","volume-title":"August","author":"Laboratories RSA","year":"1999","unstructured":"RSA Laboratories . RSA crypto challenge sets new security benchmark - 512-bit public key factored by international team of researchers , August 1999 . RSA Laboratories. RSA crypto challenge sets new security benchmark - 512-bit public key factored by international team of researchers, August 1999."},{"key":"e_1_3_2_1_42_1","volume-title":"Applied Cryptography","author":"Schneier Bruce","year":"1994","unstructured":"Bruce Schneier . Applied Cryptography . John Wiley & Sons , 1994 . Bruce Schneier. Applied Cryptography. John Wiley & Sons, 1994."},{"key":"e_1_3_2_1_43_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"534","DOI":"10.1007\/3-540-46035-7_35","volume-title":"IPSEC, WTLS,... In Advances in Cryptology -- EUROCRYPT","author":"Vaudenay S.","year":"2002","unstructured":"S. Vaudenay . Security flaws induced by CBC padding - applications to SSL , IPSEC, WTLS,... In Advances in Cryptology -- EUROCRYPT 2002 , volume 2332 of Lecture Notes in Computer Science , pages 534 -- 545 . Springer-Verlag , 2002. S. Vaudenay. Security flaws induced by CBC padding - applications to SSL, IPSEC, WTLS,... In Advances in Cryptology -- EUROCRYPT 2002, volume 2332 of Lecture Notes in Computer Science, pages 534--545. Springer-Verlag, 2002."},{"key":"e_1_3_2_1_44_1","first-page":"29","volume-title":"Proceedings of the 2nd USENIX Workshop on Electronic Commerce","author":"Wagner David","year":"1996","unstructured":"David Wagner and Bruce Schneier . Analysis of the SSL 3.0 protocol . In Proceedings of the 2nd USENIX Workshop on Electronic Commerce , pages 29 -- 40 ,Oakland, CA, November 1996 . http:\/\/www.cs.berkeley.edu\/~daw\/papers\/ssl3.0.ps. David Wagner and Bruce Schneier. Analysis of the SSL 3.0 protocol. In Proceedings of the 2nd USENIX Workshop on Electronic Commerce, pages 29--40,Oakland, CA, November 1996. http:\/\/www.cs.berkeley.edu\/~daw\/papers\/ssl3.0.ps."},{"key":"e_1_3_2_1_45_1","volume-title":"MD5, HAVAL-128 and RIPEMD","author":"Wang Xiaoyun","year":"2004","unstructured":"Xiaoyun Wang , Dengguo Feng , Xuejia Lai , and Hongbo Yu . Collisions for hash functions MD4 , MD5, HAVAL-128 and RIPEMD , 2004 . Manuscript . Available from eprint.iacr.org. Xiaoyun Wang, Dengguo Feng, Xuejia Lai, and Hongbo Yu. Collisions for hash functions MD4, MD5, HAVAL-128 and RIPEMD, 2004. Manuscript. Available from eprint.iacr.org."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/11535218_2"},{"key":"e_1_3_2_1_47_1","volume-title":"Performance comparison of public-key cryptosystems. CryptoBytes, 4(1)","author":"Wiener Michael J.","year":"1998","unstructured":"Michael J. Wiener . Performance comparison of public-key cryptosystems. CryptoBytes, 4(1) , 1998 . http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2004. Michael J. Wiener. Performance comparison of public-key cryptosystems. CryptoBytes, 4(1), 1998. http:\/\/www.rsasecurity.com\/rsalabs\/node.asp?id=2004."}],"event":{"name":"IMC07: Internet Measurement Conference","location":"San Diego California USA","acronym":"IMC07","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 7th ACM SIGCOMM conference on Internet measurement"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1298306.1298318","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1298306.1298318","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:56:08Z","timestamp":1750254968000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1298306.1298318"}},"subtitle":["current and recent practices"],"short-title":[],"issued":{"date-parts":[[2007,10,24]]},"references-count":45,"alternative-id":["10.1145\/1298306.1298318","10.1145\/1298306"],"URL":"https:\/\/doi.org\/10.1145\/1298306.1298318","relation":{},"subject":[],"published":{"date-parts":[[2007,10,24]]},"assertion":[{"value":"2007-10-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}