An Analysis of XMPP Security - PowerPoint PPT Presentation

1 / 15
About This Presentation
Title:

An Analysis of XMPP Security

Description:

Group: Chico. Introduction. XMPP: Extensible Messaging and Presence Protocol ... Group: Chico. contd. Lack of SASL channel Binding ... Group: Chico. Conclusion ... – PowerPoint PPT presentation

Number of Views:81
Avg rating:3.0/5.0
Slides: 16
Provided by: vanitade
Category:

less

Transcript and Presenter's Notes

Title: An Analysis of XMPP Security


1
An Analysis of XMPP Security
  • Instructor Prof. Richard Sinn
  • Team Members Vanita Mohite
  • Sudhir Sharma

Tuesday, 10/28/2008
2
Overview
  • Introduction
  • XMPP Implementation
  • Core components
  • Security components
  • XMPP for IM and presence
  • Security in XMPP
  • Conclusion

3
Introduction
  • XMPP Extensible Messaging and Presence Protocol
  • Used for IM, text chat, video calls
  • Contains XML streams
  • Founded by the Jabber Software Foundation and is
    Open Technology
  • Uses TCP/IP connection

4
XMPP Implementation
  • XMPP has three main components
  • Core components
  • Security components
  • XMPP for IM and Presence

5
Core components
  • XMPP Client
  • XMPP Server
  • Gateway of foreign network

Figure 1 XMPP core components 4.
6
contd.
  • Attributes in XML stream
  • ltmessage/gt
  • ltpresence/gt
  • ltid/gt

7
Security components
  • TLS (Transport Layer Security)
  • SASL (Simple Authentication and Security Layer
    Protocol)

Figure 2 Security layers in XMPP 4.
8
(No Transcript)
9
XMPP for IM and presence
  • Five types of messages that are sent in XMPP
  • Unicast
  • Broadcast
  • Multicast
  • Normal
  • Error

10
contd.
  • Three elements for presence message
  • Show
  • Status
  • Presence service

11
Security in XMPP
  • High Security
  • Certificate validation
  • Client- server communication
  • Server- Server communication
  • Protocol layers

12
contd.
  • Lack of SASL channel Binding with TLS
  • Technology implementations
  • Firewalls
  • Base64
  • Stringprep Profiles
  • Nodeprep
  • Resourceprep

13
Conclusion
  • Jabber Software Foundation is continuing their
    research in improvising security for XMPP

14
References
  • 1 XMPP Security. Retrieved, on 09/14/2008, from
    http//xmpp .org/tech/overview.shtml.
  • 2 XMPP Security. Retrieved, on 09/14/2008, from
    http//www.ietf .org/rfc/rfc3920.txt.
  • 3 Peter Saint-Andre. Streaming XML with
    Jabber/XMPP
  • Found in IEEE Internet Computing, Published
    by the IEEE Computer Society
  • 4 Pin Nei. An open standard for instant
    messaging eXtensible Messaging and Presence
    Protocol (XMPP). Found in www.tml.tkk.fi/Publicat
    ions/C/21/nie_ready.pdf.

15
  • Thank you
Write a Comment
User Comments (0)
About PowerShow.com