首页> 外文会议>International symposium on research in attacks, intrusions and defenses >Privacy is Not an Option: Attacking the IPv6 Privacy Extension
【24h】

Privacy is Not an Option: Attacking the IPv6 Privacy Extension

机译:隐私不是一种选择:攻击IPv6隐私扩展

获取原文

摘要

The IPv6 privacy extension introduces temporary addresses to protect against address-based correlation, i.e., the attribution of different transactions to the same origin using addresses, and is considered as state-of-the-art mechanism for privacy protection in IPv6. In this paper, we scrutinize the extension's capability for protection by analyzing its algorithm for temporary address generation in detail. We develop an attack that is based on two insights and shows that the notion of protection is false: First, randomization is scarce and future identifiers can be predicted once the algorithm's internal state is known. Second, a victim's temporary addresses form a side channel and allow an adversary to synchronize to this internal state. Finally, we highlight mitigation strategies, and recommend a revision of the extension's specification.
机译:IPv6隐私扩展引入了临时地址以防止基于地址的关联,即使用地址将不同交易归于同一来源,并且被认为是IPv6中隐私保护的最新机制。在本文中,我们通过详细分析扩展名的临时地址生成算法来仔细检查扩展名的保护能力。我们基于两种见解开发了一种攻击,并表明保护的概念是错误的:首先,随机性稀少,一旦知道算法的内部状态,就可以预测将来的标识符。其次,受害人的临时地址形成了一条旁道,并允许对手同步到此内部状态。最后,我们重点介绍缓解策略,并建议对扩展规范进行修订。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号