首页> 外文会议>IEEE Symposium on Security and Privacy >Deniable password snatching: on the possibility of evasive electronic espionage
【24h】

Deniable password snatching: on the possibility of evasive electronic espionage

机译:拒绝密码抢夺:关于避免电子间谍活动的可能性

获取原文

摘要

Cryptovirology has recently been introduced as a means of mounting active viral attacks using public key cryptography. It has been shown to be a tool for extortion attacks and "electronic warfare", where attacks are mounted against information resources. The natural question to ask is whether Cryptovirology is also useful in the area of spying via malware. We demonstrate that Cryptovirology does help in "electronic espionage" and allows the spy to conceal his or her identity (as well as past collected information). Specifically, we present an attack that can be mounted by a cryptotrojan that allows the attacker to gather information (passwords) from a system in such a way that the attacker cannot be proven guilty beyond reasonable doubt. That is, even if the attacker is under surveillance on the local machine from when he first attacks the target machine, to when he obtains the passwords, and even if the leaked information is made available to the attacker exclusively, he still cannot be caught. The threat is made possible by the combination of public key cryptography, probabilistic encryption, and the use of public information (I/O or communication) channels which together form a "secure receiver-anonymous channel". The machine can be standalone or networked. What we learn from the attack is extracted as general tools and basic principles for "espionage attacks".
机译:最近被引入了密码学作为使用公钥加密安装有源病毒攻击的手段。它已被证明是敲诈勒索攻击的工具和“电子战”,其中攻击安装在信息资源上。要问的自然问题是阴道血管学在通过恶意软件间谍区域也有用。我们证明隐窝学确实有助于“电子间谍”,并允许间谍隐瞒他或她的身份(以及过去收集的信息)。具体而言,我们提出了一种可以由CryptoTrojan安装的攻击,允许攻击者从系统中收集信息(密码),以便攻击者不能被证明超出合理怀疑。也就是说,即使攻击者在首次攻击目标机器时攻击当地机器时,在获得密码时,即使泄露的信息专门用于攻击者,他仍然无法捕获。通过公钥密码学,概率加密和使用公共信息(I / O或通信)信道的组合来实现威胁,它们一起形成“安全接收器 - 匿名信道”。机器可以是独立的或网络。我们从攻击中学到的内容被提取为“间谍攻击”的一般工具和基本原则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号