A Systematic Analysis of the Juniper Dual EC Incident

A Systematic Analysis of the Juniper Dual EC Incident
复制标题

Juniper双EC事件系统分析

DOI:
--
复制
发表时间:
2016
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
R. Weinmann
R. Weinmann
中科院分区:
--
文献类型:
--
作者:
Stephen Checkoway;Shaanan N. Cohney;Christina Garman;M. Green;N. Heninger;Jacob Maskiewicz;E. Rescorla;H. Shacham;R. Weinmann

文献摘要

被引文献

相似文献

2015年12月,瞻博网络宣布了多个安全漏洞,这些漏洞源于其NetScreen VPN路由器的操作系统ScreenOS中未经授权的代码。这些漏洞中更复杂的是被动VPN解密功能,通过更改双EC伪随机数发生器使用的椭圆曲线点之一来启用。在本文中,我们描述了ScreenOS随机性和VPN密钥建立协议子系统的完全独立分析的结果,我们在此事件中进行了响应。虽然Dual EC对于可以选择椭圆曲线参数的攻击者来说是不安全的,但Juniper在2013年声称ScreenOS包括针对这种类型攻击的对策。我们发现,与Juniper的公开声明相反,自2008年以来,ScreenOS VPN实施一直容易受到选择双EC曲线点的攻击者的被动利用。此漏洞的产生是由于Juniper的对策中存在明显的缺陷,以及在2008年发布的单一版本中包含Dual EC时同时引入的一系列更改。我们证明了一个真实的NetScreen设备上的漏洞,通过修改固件安装我们自己的参数,我们表明,它是可以被动地解密单独的VPN会话隔离,而不观察任何其他网络流量。我们研究了在野外被动指纹ScreenOS实现的可能性。这一事件是一个重要的例子,说明随机数生成、工程和验证的指导方针在实践中可能会失败。
In December 2015, Juniper Networks announced multiple security vulnerabilities stemming from unauthorized code in ScreenOS, the operating system for their NetScreen VPN routers. The more sophisticated of these vulnerabilities was a passive VPN decryption capability, enabled by a change to one of the elliptic curve points used by the Dual EC pseudorandom number generator. In this paper, we describe the results of a full independent analysis of the ScreenOS randomness and VPN key establishment protocol subsystems, which we carried out in response to this incident. While Dual EC is known to be insecure against an attacker who can choose the elliptic curve parameters, Juniper had claimed in 2013 that ScreenOS included countermeasures against this type of attack. We find that, contrary to Juniper's public statements, the ScreenOS VPN implementation has been vulnerable since 2008 to passive exploitation by an attacker who selects the Dual EC curve point. This vulnerability arises due to apparent flaws in Juniper's countermeasures as well as a cluster of changes that were all introduced concurrently with the inclusion of Dual EC in a single 2008 release. We demonstrate the vulnerability on a real NetScreen device by modifying the firmware to install our own parameters, and we show that it is possible to passively decrypt an individual VPN session in isolation without observing any other network traffic. We investigate the possibility of passively fingerprinting ScreenOS implementations in the wild. This incident is an important example of how guidelines for random number generation, engineering, and validation can fail in practice.