The Experts below are selected from a list of 66 Experts worldwide ranked by ideXlab platform
Bo Meng - One of the best experts on this subject based on the ideXlab platform.
-
A Security Analysis Method for Security Protocol Implementations Based on Message Construction
Applied Sciences, 2018Co-Authors: Lili Yao, Chin-tser Huang, Dejun Wang, Bo MengAbstract:Security protocols are integral to the protection of cyberspace against malicious attacks. Therefore, it is important to be confident in the security of a security protocol. In previous years, people have worked on security of security protocol abstract specification. However, in recent years, people have found that this is not enough and have begun focusing on security protocol implementation. In order to evaluate the security of security protocol implementations, in this paper, firstly, we proposed the Message Construction to Security Protocol Implementation (MCSPI), a Message Construction method based on application programming interface (API) traces, which automatically generates the constructed client valid request Messages. Then, we presented the Security Analysis Scheme (SAS), a security analysis scheme that generates an abstract model of a security protocol server. Next, we proposed a security analysis method to evaluate the security of security protocol implementations on the basis of constructed client request Messages generated with MCSPI, corresponding to the server-side response Message and server-side abstract model produced by SAS. Finally, we implemented the Security Protocol Implementation Analysis (SPIA) tool to generate client valid request Messages and a server-side abstract model to assist in evaluating security protocol implementations. In our experiments, we tested Tencent QQ mail system version 2017 and RSAAuth system and found that RSAAuth is vulnerable and its server has only security checks for user password, while Tencent QQ mail system version 2017 is more secure and has strong security restrictions at server-side besides security checks for user password.
Alexander Ollongren - One of the best experts on this subject based on the ideXlab platform.
-
Large-size Message Construction for ETI validation of Lingua Cosmica
Acta Astronautica, 2014Co-Authors: Alexander OllongrenAbstract:Abstract The paper addresses the validation issue for the Lingua Cosmica system: have the results of sequences of reasoning (i.e. conclusions) a universal validity in some sense? LINCOS verifications of a selected set of representative statements are considered. They are compared with proofs of the same statements obtained by means of an existing proof system in computer science. The treatment indicates how formalised descriptive logic reasoning can be transposed from one system to the other. As this kind of reasoning is not bound to a specific system, it possesses an aspect of unversality.
-
large size Message Construction for eti logical existence expressed in lingua cosmica
Acta Astronautica, 2013Co-Authors: Alexander Ollongren, Douglas A. VakochAbstract:Abstract The concept of logical existence is embedded in Lingua Cosmica, a formal linguistic system intended for use in interstellar communication between intelligent species in the Galaxy.
-
Large-size Message Construction for ETI: Inductive self-interpretation in LINCOS
Acta Astronautica, 2010Co-Authors: Alexander OllongrenAbstract:Ingredients of the author's Lingua Cosmica for communication with extra-terrestrial intelligent beings are examined with self-interpretation in mind. The most important ingredients for that purpose are inductive definitions. These definitions contain ordered sequences of induction hypotheses, identified by mutually distinctive constructors. If an assertion involving an inductive definition is to be verified, all induction hypotheses must be taken into account, i.e. they must be eliminated one by one. The implementation of the elimination procedure can be expressed within LINCOS itself. Therefore the system admits self-interpretation.
Lili Yao - One of the best experts on this subject based on the ideXlab platform.
-
A Security Analysis Method for Security Protocol Implementations Based on Message Construction
Applied Sciences, 2018Co-Authors: Lili Yao, Chin-tser Huang, Dejun Wang, Bo MengAbstract:Security protocols are integral to the protection of cyberspace against malicious attacks. Therefore, it is important to be confident in the security of a security protocol. In previous years, people have worked on security of security protocol abstract specification. However, in recent years, people have found that this is not enough and have begun focusing on security protocol implementation. In order to evaluate the security of security protocol implementations, in this paper, firstly, we proposed the Message Construction to Security Protocol Implementation (MCSPI), a Message Construction method based on application programming interface (API) traces, which automatically generates the constructed client valid request Messages. Then, we presented the Security Analysis Scheme (SAS), a security analysis scheme that generates an abstract model of a security protocol server. Next, we proposed a security analysis method to evaluate the security of security protocol implementations on the basis of constructed client request Messages generated with MCSPI, corresponding to the server-side response Message and server-side abstract model produced by SAS. Finally, we implemented the Security Protocol Implementation Analysis (SPIA) tool to generate client valid request Messages and a server-side abstract model to assist in evaluating security protocol implementations. In our experiments, we tested Tencent QQ mail system version 2017 and RSAAuth system and found that RSAAuth is vulnerable and its server has only security checks for user password, while Tencent QQ mail system version 2017 is more secure and has strong security restrictions at server-side besides security checks for user password.
Dejun Wang - One of the best experts on this subject based on the ideXlab platform.
-
A Security Analysis Method for Security Protocol Implementations Based on Message Construction
Applied Sciences, 2018Co-Authors: Lili Yao, Chin-tser Huang, Dejun Wang, Bo MengAbstract:Security protocols are integral to the protection of cyberspace against malicious attacks. Therefore, it is important to be confident in the security of a security protocol. In previous years, people have worked on security of security protocol abstract specification. However, in recent years, people have found that this is not enough and have begun focusing on security protocol implementation. In order to evaluate the security of security protocol implementations, in this paper, firstly, we proposed the Message Construction to Security Protocol Implementation (MCSPI), a Message Construction method based on application programming interface (API) traces, which automatically generates the constructed client valid request Messages. Then, we presented the Security Analysis Scheme (SAS), a security analysis scheme that generates an abstract model of a security protocol server. Next, we proposed a security analysis method to evaluate the security of security protocol implementations on the basis of constructed client request Messages generated with MCSPI, corresponding to the server-side response Message and server-side abstract model produced by SAS. Finally, we implemented the Security Protocol Implementation Analysis (SPIA) tool to generate client valid request Messages and a server-side abstract model to assist in evaluating security protocol implementations. In our experiments, we tested Tencent QQ mail system version 2017 and RSAAuth system and found that RSAAuth is vulnerable and its server has only security checks for user password, while Tencent QQ mail system version 2017 is more secure and has strong security restrictions at server-side besides security checks for user password.
Chin-tser Huang - One of the best experts on this subject based on the ideXlab platform.
-
A Security Analysis Method for Security Protocol Implementations Based on Message Construction
Applied Sciences, 2018Co-Authors: Lili Yao, Chin-tser Huang, Dejun Wang, Bo MengAbstract:Security protocols are integral to the protection of cyberspace against malicious attacks. Therefore, it is important to be confident in the security of a security protocol. In previous years, people have worked on security of security protocol abstract specification. However, in recent years, people have found that this is not enough and have begun focusing on security protocol implementation. In order to evaluate the security of security protocol implementations, in this paper, firstly, we proposed the Message Construction to Security Protocol Implementation (MCSPI), a Message Construction method based on application programming interface (API) traces, which automatically generates the constructed client valid request Messages. Then, we presented the Security Analysis Scheme (SAS), a security analysis scheme that generates an abstract model of a security protocol server. Next, we proposed a security analysis method to evaluate the security of security protocol implementations on the basis of constructed client request Messages generated with MCSPI, corresponding to the server-side response Message and server-side abstract model produced by SAS. Finally, we implemented the Security Protocol Implementation Analysis (SPIA) tool to generate client valid request Messages and a server-side abstract model to assist in evaluating security protocol implementations. In our experiments, we tested Tencent QQ mail system version 2017 and RSAAuth system and found that RSAAuth is vulnerable and its server has only security checks for user password, while Tencent QQ mail system version 2017 is more secure and has strong security restrictions at server-side besides security checks for user password.