首页> 外文会议>Foundations and applications of security analysis : Revised selected papers >Validating Security Protocols under the General Attacker
【24h】

Validating Security Protocols under the General Attacker

机译:验证通用攻击者下的安全协议

获取原文
获取原文并翻译 | 示例

摘要

Security protocols have been analysed using a variety of tools and focusing on a variety of properties. Most findings assume the ever so popular Dolev-Yao threat model. A more recent threat model called the Rational Attacker [1] sees each protocol participant decide whether or not to conform to the protocol upon their own cost/benefit analysis. Each participant neither colludes nor shares knowledge with anyone, a feature that rules out the applicability of existing equivalence results in the Dolev-Yao model. Aiming at mechanical validation, we abstract away the actual cost/benefit analysis and obtain the General Attacker threat model, which sees each principal blindly act as a Dolev-Yao attacker.rnThe analysis of security protocols under the General Attacker threat model brings forward yet more insights: retaliation attacks and anticipation attacks are our main findings, while the tool support can scale up to the new analysis at a negligible price. The general threat model for security protocols based on set-rewriting that was adopted in AVISPA [2] is leveraged so as to express the General Attacker. The state-of-the-art model checker SATMC [3] is then used to automatically validate a protocol under the new threats, so that retaliation and anticipation attacks can automatically be found.
机译:已使用各种工具并着重于各种属性对安全协议进行了分析。大多数发现均假设Dolev-Yao威胁模型如此流行。最近一种称为Rational Attacker [1]的威胁模型,可以看到每个协议参与者根据自己的成本/收益分析来决定是否符合该协议。每个参与者都不会与任何人串通或共享知识,该功能排除了Dolev-Yao模型中现有等效结果的适用性。针对机械验证,我们提取了实际的成本/收益分析,得到了通用攻击者威胁模型,该模型将每个主体都盲目地充当了Dolev-Yao攻击者。rn在通用攻击者威胁模型下对安全协议的分析提出了更多见解:报复攻击和预期攻击是我们的主要发现,而工具支持可以以微不足道的价格扩展到新分析。利用AVISPA [2]中采用的基于集重写的安全协议通用威胁模型来表达通用攻击者。然后,使用最先进的模型检查器SATMC [3]在新的威胁下自动验证协议,从而可以自动找到报复和预期攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号