Where did I leave my keys?: lessons from the Juniper Dual EC incident

Where did I leave my keys?: lessons from the Juniper Dual EC incident
复制标题

我把钥匙落在哪里了?:Juniper Dual EC 事件的教训

DOI:
10.1145/3266291
复制
发表时间:
2018
影响因子:
22.7
通讯作者:
Shacham, Hovav
Shacham, Hovav
中科院分区:
计算机科学3区
文献类型:
--
作者:
Checkoway, Stephen;Maskiewicz, Jacob;Garman, Christina;Fried, Joshua;Cohney, Shaanan;Green, Matthew;Heninger, Nadia;Weinmann, Ralf-Philipp;Rescorla, Eric;Shacham, Hovav

文献摘要

相似文献

2015年12月,瞻博网络宣布了多个安全漏洞,这些漏洞源于其NetScreen虚拟专用网络(VPN)路由器的操作系统ScreenOS中未经授权的代码。这些漏洞中更复杂的是被动VPN解密功能,通过更改双椭圆曲线(EC)伪随机数生成器使用的参数之一来启用。在本文中,我们描述了针对此事件对ScreenOS随机性和VPN密钥建立协议子系统进行完全独立分析的结果。虽然Dual EC对于可以选择椭圆曲线参数的攻击者来说是不安全的,但Juniper在2013年声称ScreenOS包括针对这种类型攻击的对策。我们发现,与Juniper的公开声明相反,自2008年以来,ScreenOS VPN实施一直容易受到选择双EC曲线点的攻击者的被动利用。此漏洞是由于Juniper的对策中存在缺陷以及在2008年单一版本中包含Dual EC时同时引入的一系列更改引起的。我们证明了一个真实的NetScreen设备上的漏洞,通过修改固件安装我们自己的参数,我们表明,它是可以被动地解密单独的VPN会话隔离,而不观察任何其他网络流量。这一事件是一个重要的例子,说明随机数生成、工程和验证的指导方针在实践中可能会失败。此外,它使人进一步怀疑设计美国和其他地方执法机构所设想的那种安全的“特殊进入”或“钥匙托管”办法是否切实可行。
In December 2015, Juniper Networks announced multiple security vulnerabilities stemming from unauthorized code in ScreenOS, the operating system for their NetScreen Virtual Private Network (VPN) routers. The more sophisticated of these vulnerabilities was a passive VPN decryption capability, enabled by a change to one of the parameters used by the Dual Elliptic Curve (EC) pseudorandom number generator.In this paper, we described the results of a full independent analysis of the ScreenOS randomness and VPN key establishment protocol subsystems, which we carried out in response to this incident. While Dual EC is known to be insecure against an attacker who can choose the elliptic curve parameters, Juniper had claimed in 2013 that ScreenOS included countermeasures against this type of attack. We find that, contrary to Juniper's public statements, the ScreenOS VPN implementation has been vulnerable to passive exploitation by an attacker who selects the Dual EC curve point since 2008. This vulnerability arises due to flaws in Juniper's countermeasures as well as a cluster of changes that were all introduced concurrently with the inclusion of Dual EC in a single 2008 release. We demonstrate the vulnerability on a real NetScreen device by modifying the firmware to install our own parameters, and we show that it is possible to passively decrypt an individual VPN session in isolation without observing any other network traffic. This incident is an important example of how guidelines for random number generation, engineering, and validation can fail in practice. Additionally, it casts further doubt on the practicality of designing a safe "exceptional access" or "key escrow" scheme of the type contemplated by law enforcement agencies in the United States and elsewhere.