首页> 外文期刊>Computers & Security >Design guidelines for security protocols to prevent replay & parallel session attacks
【24h】

Design guidelines for security protocols to prevent replay & parallel session attacks

机译:安全协议的设计准则,以防止重放和并行会话攻击

获取原文
获取原文并翻译 | 示例

摘要

This work is concerned with the design of security protocols. These protocols are susceptible to intruder attacks and their security compromised if weaknesses in the protocols' design are evident. In this paper a new analysis is presented on the reasons why security protocols are vulnerable to replay and parallel session attack and based on this analysis a new set of design guidelines to ensure resistance to these attacks is proposed. The guidelines are general purpose so as to encompass a wide spectrum of security protocols. Further, an empirical study on the effectiveness of the proposed guidelines is carried out on a set of protocols, incorporating those that are known to be vulnerable to replay or parallel session attacks as well as some amended versions that are known to be free of these weaknesses. The goal of this study is to establish conformance of the set of protocols with the proposed design guidelines. The results of the study show that any protocol following the design guidelines can be considered free of weaknesses exploitable by replay or parallel session attacks. On the other hand, if non-conformance of a protocol with the design guidelines is determined, then the protocol is vulnerable to replay or parallel session attacks.
机译:这项工作与安全协议的设计有关。如果协议设计中的弱点很明显,这些协议就容易受到入侵者的攻击,并且其安全性也会受到损害。本文针对安全协议为何易受重放和并行会话攻击的原因进行了新的分析,并在此分析的基础上提出了一套新的设计指南,以确保抵抗这些攻击。该准则是通用的,目的是涵盖各种安全协议。此外,还对一套协议的有效性进行了实证研究,并结合了一些已知的易受重放或并行会话攻击的协议以及一些没有这些弱点的修订版本。 。这项研究的目的是建立与提议的设计指南一致的协议集。研究结果表明,遵循设计准则的任何协议都可以视为没有重播或并行会话攻击可利用的弱点。另一方面,如果确定不符合设计准则的协议,则该协议容易受到重放或并行会话攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号