Retaliation against protocol attacks
Retaliation against protocol attacks
复制标题
针对协议攻击的报复
DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
--
通讯作者:
Stefano Bistarelli
中科院分区:
文献类型:
--
作者:
G. Bella;Stefano Bistarelli
Security protocols intend to give their parties reasonable assurance that certain security properties will protect their commu- nication session. However, the literature confirms that the protocols may suffer subtle and hidden attacks. Flawed protocols are custom- arily sent back to the design process, but the costs of reengineer- ing a deployed protocol may be prohibitive. This paper outlines the concept of retaliation: who would steal a sum of money today, should this pose significant risks of having twice as much stolen back tomorrow? When ethics is left behind, attacks are always bal- anced decisions: if an attack can be retaliated, the economics of security may convince the attacker to refrain from attacking, and us to live with a flawed protocol. This new perspective requires a new threat model where any party may decide to subvert the pro- tocol for his own sake, depending on the risks of retaliation. This threat model, which for example is also suitable to studying non- repudiation protocols, seems more appropriate than the Dolev-Yao model to the present technological/social setting. It is demonstrated that machine-assisted protocol verification can can effectively be adapted to the new threat model.