Retaliation against protocol attacks

Retaliation against protocol attacks
复制标题

针对协议攻击的报复

DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
--
通讯作者:
Stefano Bistarelli
Stefano Bistarelli
中科院分区:
--
文献类型:
--
作者:
G. Bella;Stefano Bistarelli

文献摘要

被引文献

相似文献

安全协议打算给他们的当事人合理的保证,某些安全属性将保护他们的通信会话。然而,文献证实,协议可能遭受微妙和隐藏的攻击。有缺陷的协议通常会被送回设计过程,但重新设计已部署协议的成本可能会令人望而却步。这篇论文概述了报复的概念:今天谁会偷一笔钱,这是否会带来明天被偷两倍的巨大风险?当道德被抛在后面时,攻击总是平衡的决定:如果攻击可以被报复,安全经济可能会说服攻击者避免攻击,而我们则接受有缺陷的协议。这种新的观点需要一种新的威胁模型,在这种模型中,任何一方都可能为了自己的利益而决定破坏协议,这取决于报复的风险。该威胁模型也适用于研究不可抵赖协议,似乎比Dolev-Yao模型更适合当前的技术/社会环境。结果表明,机器辅助协议验证能够有效地适应新的威胁模型。
Security protocols intend to give their parties reasonable assurance that certain security properties will protect their commu- nication session. However, the literature confirms that the protocols may suffer subtle and hidden attacks. Flawed protocols are custom- arily sent back to the design process, but the costs of reengineer- ing a deployed protocol may be prohibitive. This paper outlines the concept of retaliation: who would steal a sum of money today, should this pose significant risks of having twice as much stolen back tomorrow? When ethics is left behind, attacks are always bal- anced decisions: if an attack can be retaliated, the economics of security may convince the attacker to refrain from attacking, and us to live with a flawed protocol. This new perspective requires a new threat model where any party may decide to subvert the pro- tocol for his own sake, depending on the risks of retaliation. This threat model, which for example is also suitable to studying non- repudiation protocols, seems more appropriate than the Dolev-Yao model to the present technological/social setting. It is demonstrated that machine-assisted protocol verification can can effectively be adapted to the new threat model.