What are multi-protocol guessing attacks and how to prevent them

S. Malladi1, J. Alves-Foss1
1Center for Secure and Dependable Systems, University of Idaho Moscow, ID

Tóm tắt

A guessing attack on a security protocol is an attack where an attacker guesses a poorly chosen secret (usually a low-entropy user password) and then seeks to verify that guess using other information. Past efforts to address guessing attacks in terms of design or analysis considered only protocols executed in isolation. However, security protocols are rarely executed in isolation and reality is always a case of mixed-protocols. In this paper, we introduce new types of attacks called multi-protocol guessing attacks, which can exist when protocols are mixed. We develop a systematic procedure to analyze protocols subject to guessing attacks and use this procedure to derive some syntactic conditions to be followed, in order for a protocol to be secure against multi-protocol guessing attacks. We then use the strand space framework to prove that a protocol will remain secure, given that these conditions are followed, by modeling the conditions within the framework. We illustrate these concepts using the Mellovin and Berritt protocol (EKE) as an example.

Từ khóa

#Information security #Cryptography #Cryptographic protocols #Communication channels #Costs #Humans #Conferences #Isolation technology #Collaborative work #International collaboration

Tài liệu tham khảo

10.1109/CSFW.2000.856942 kohl, 1993, The Kerberos network authentication service (v5), RFC 1510 lowe, 1996, Breaking and fixing the Needham-Schroeder public-key protocol using FDR, proceedings of TACAS, 1055, 147 lowe, 2002, Analyzing protocols subject to guessing attacks, Workshop on Issues in the Theory of Security (WITS) malladi, 2002, Preventing Guessing Attacks Using Fingerprint Biometrics, Proceedings of 2002 International Conference on Security and Management SAM02 10.1145/359168.359172 10.1145/155848.155852 schneider, 1997, Verifying authentication protocols with CS P, Proceedings of the 10th IEEE Computer Security Foundations Workshop, 10.1109/CSFW.1997.596775 fábrega, 1998, Why is a security protocol correct?, IEEE Symposium on Security and Privacy dierks, 1999, The TLS protocol. RFC 2246 fábrega, 1999, Strand spaces: Proving security protocols correct, Journal of Computer Security, 7, 191, 10.3233/JCS-1999-72-304 10.1109/CSFW.1999.779763 guttman, 1998, Strand Spaces and Protocol Security Goals, Foundations of Security Analysis and Design 10.1109/49.223865 10.1109/CSFW.2000.856933 10.1109/RISP.1992.213269 10.1109/CSFW.2000.856923