首页> 外文OA文献 >Detecting and Preventing Type Flaws: a Control Flow Analysis with tags
【2h】

Detecting and Preventing Type Flaws: a Control Flow Analysis with tags

机译:检测和防止类型缺陷:带有标签的控制流分析

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

A type flaw attack on a security protocol is an attack where an honest principal is cheated on interpreting a field in a message as the one with a type other than the intended one. In this paper, we shall present an extension of the LySa calculus with tags attached to each field, indicating the intended types. We developed a control flow analysis for analysing the extended LySa, which over-approximates all the possible behaviour of a protocol and hence is able to capture any type confusion that may happen during the protocol execution. The control flow analysis has been applied to a number of security protocols, either subject to type flaw attacks or not. The results show that it is able to capture type flaw attacks on those security protocols.
机译:对安全协议的类型缺陷攻击是指一种诚实的主体被欺骗将消息中的字段解释为具有非预期类型的​​字段的攻击。在本文中,我们将介绍LySa演算的扩展,在每个字段上附加标签,以指示预期的类型。我们开发了用于分析扩展LySa的控制流分析,该分析过度逼近了协议的所有可能行为,因此能够捕获协议执行期间可能发生的任何类型的混淆。控制流分析已应用于多种安全协议,无论它们是否受到类型缺陷攻击。结果表明,它能够捕获那些安全协议上的类型缺陷攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号