A Surfeit of SSH Cipher Suites

A Surfeit of SSH Cipher Suites
复制标题

过多的 SSH 密码套件

DOI:
10.1145/2976749.2978364
复制
发表时间:
2016
期刊:
--
影响因子:
--
通讯作者:
Albrecht M
Albrecht M
中科院分区:
--
文献类型:
--
作者:
Albrecht M

文献摘要

参考文献

被引文献

相似文献

这项工作提出了一个系统的分析,在互联网上使用的SSH的对称加密模式,提供部署统计数据,新的攻击,并广泛使用的模式的安全性证明。我们报告的部署统计数据基于2015年底和2016年初进行的两次互联网范围的SSH服务器扫描。Dropbear和OpenSSH实现在我们的扫描中占主导地位。从我们的第一次扫描中,我们发现130,980个OpenSSH服务器仍然容易受到Albrecht等人的CBC模式特定攻击。(IEEE S & P 2009),而我们发现另外20,000个OpenSSH服务器容易受到CBC模式的新攻击,该攻击绕过了OpenSSH 5.2中引入的反措施,以击败Albrecht等人的攻击。在我们的第一次扫描中,有449个Dropbear服务器容易受到原始CBC模式攻击的变种。从积极的方面来看,我们为其他流行的SSH加密模式提供了正式的安全分析,即ChaCha20-Poly1305,通用的Encrypt-then-MAC和AES-GCM。我们的证明持有详细的伪代码描述这些算法在OpenSSH中实现。我们的证明使用了Boldyreva等人专门为SSH设置开发的“碎片解密”安全模型的修正和扩展版本(Eurocrypt 2012)。这些证明为SSH中CBC模式加密的替代方案提供了强有力的机密性和完整性保证。然而,我们也表明,这些替代品不满足额外的,理想的安全概念(被动和主动攻击下的边界隐藏,拒绝服务抗性),正式由Boldyreva等人。
This work presents a systematic analysis of symmetric encryption modes for SSH that are in use on the Internet, providing deployment statistics, new attacks, and security proofs for widely used modes. We report deployment statistics based on two Internet-wide scans of SSH servers conducted in late 2015 and early 2016. Dropbear and OpenSSH implementations dominate in our scans. From our first scan, we found 130,980 OpenSSH servers that are still vulnerable to the CBC-mode-specific attack of Albrecht et al. (IEEE S&P 2009), while we found a further 20,000 OpenSSH servers that are vulnerable to a new attack on CBC-mode that bypasses the counter-measures introduced in OpenSSH 5.2 to defeat the attack of Albrecht et al. At the same time, 886,449 Dropbear servers in our first scan are vulnerable to a variant of the original CBC-mode attack. On the positive side, we provide formal security analyses for other popular SSH encryption modes, namely ChaCha20-Poly1305, generic Encrypt-then-MAC, and AES-GCM. Our proofs hold for detailed pseudo-code descriptions of these algorithms as implemented in OpenSSH. Our proofs use a corrected and extended version of the "fragmented decryption" security model that was specifically developed for the SSH setting by Boldyreva et al. (Eurocrypt 2012). These proofs provide strong confidentiality and integrity guarantees for these alternatives to CBC-mode encryption in SSH. However, we also show that these alternatives do not meet additional, desirable notions of security (boundary-hiding under passive and active attacks, and denial-of-service resistance) that were formalised by Boldyreva et al.
DOI: 10.1007/978-3-540-30556-9_27
发表时间: 2004-12
期刊: --
影响因子: --
作者:
D. McGrew;J. Viega
通讯作者: D. McGrew;J. Viega
DOI: --
发表时间: 2013
期刊: Fast Software Encryption Workshop
影响因子: --
作者:
A. Boldyreva;Jean Paul Degabriele;K. Paterson;Martijn Stam
通讯作者: Martijn Stam
chacha20-poly1305@openssh.com 经过身份验证的加密密码
DOI: --
发表时间: 2015
期刊:
影响因子: --
作者:
D. Miller;S. Josefsson
通讯作者: S. Josefsson
用于安全外壳传输层协议的 AES Galois 计数器模式
DOI: --
发表时间: 2009
期刊: Request for Comments
影响因子: --
作者:
Kevin M. Igoe;J. Solinas
通讯作者: J. Solinas
Secure Shell (SSH) 传输层协议的 SHA-2 数据完整性验证
DOI: --
发表时间: 2012
期刊: Request for Comments
影响因子: --
作者:
Denis Bider;Mark D. Baushke
通讯作者: Mark D. Baushke