首页> 外文期刊>Journal of Information Warfare >Malware-based Information Leakage over IPSec Tunnels
【24h】

Malware-based Information Leakage over IPSec Tunnels

机译:基于恶意软件的信息泄露IPSec隧道

获取原文
获取原文并翻译 | 示例
           

摘要

IPSec-based protocols are often presented by practitioners of information security as an efficient solution to prevent attacks against data exchange. More generally, use of encryption to protect communication channels or to seclude sensitive networks is seen as the ultimate defence. Unfortunately, this confidence is illusory since such "armoured" protocols can be manipulated or corrupted by an attacker to leak information whenever an access is managed with simple user's permission. In this paper, we present how an attacker and/or a malware can subvert and bypass IPSec-like protocols to leak data from the system under attack. By using a covert channel, we show how to code the information to be stolen, how to insert it in the legitimate encrypted traffic and finally collect/decode the information on the attacker's side. We first present how to exploit the covert channel and to steal sensitive data without triggering any alert. Subsequently, the detailed results of extensive experiments to validate the attack techniques on an operational level are given. Finally, some potential prevention and protection techniques are presented to limit such attacks. However, this analysis demonstrates that residual weaknesses are bound to remain unless the communication protocols involved are significantly modified,.
机译:基于IPSec的协议通常由信息安全的从业者作为一种有效的解决方案来呈现,以防止攻击数据交换。更一般地说,使用加密来保护通信信道或将敏感网络视为最终的防御。不幸的是,这种信心是虚幻的,因为可以通过攻击者被操纵或损坏这样的“装甲”协议,只要使用简单的用户权限管理访问就会泄漏信息。在本文中,我们介绍了攻击者和/或恶意软件如何颠覆和绕过类似IPSec的协议以攻击系统中的数据。通过使用封面通道,我们展示了如何将信息编写被盗,如何将其插入合法的加密流量,最后收集/解码攻击者侧的信息。我们首先介绍如何利用封面通道并窃取敏感数据而不触发任何警报。随后,给出了在运行水平上验证攻击技术的广泛实验的详细结果。最后,提出了一些潜在的预防和保护技术来限制此类攻击。然而,除非所涉及的通信协议显着修改,否则该分析表明剩余弱点仍然保持留下。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号