The Experts below are selected from a list of 645 Experts worldwide ranked by ideXlab platform
Christopher Walstad - One of the best experts on this subject based on the ideXlab platform.
-
Breaking and fixing public-key Kerberos
Information and Computation, 2008Co-Authors: Iliano Cervesato, Aaron D. Jaggard, Andre Scedrov, Joe-kai Tsay, Christopher WalstadAbstract:AbstractWe report on a man-in-the-middle attack on PKINIT, the public key extension of the widely deployed Kerberos 5 authentication protocol. This flaw allows an attacker to impersonate Kerberos administrative principals (KDC) and end-servers to a client, hence breaching the authentication guarantees of Kerberos. It also gives the attacker the keys that the KDC would normally generate to encrypt the service requests of this client, hence defeating confidentiality as well. The discovery of this attack caused the IETF to change the specification of PKINIT and Microsoft to release a Security Update for some Windows operating systems. We discovered this attack as part of an ongoing formal analysis of the Kerberos protocol suite, and we have formally verified several possible fixes to PKINIT—including the one adopted by the IETF—that prevent our attack as well as other authentication and secrecy properties of Kerberos with PKINIT
-
ASIAN - Breaking and fixing public-key Kerberos
Information & Computation, 2006Co-Authors: Iliano Cervesato, Aaron D. Jaggard, Andre Scedrov, Joe-kai Tsay, Christopher WalstadAbstract:We report on a man-in-the-middle attack on PKINIT, the public key extension of the widely deployed Kerberos 5 authentication protocol. This flaw allows an attacker to impersonate Kerberos administrative principals (KDC) and end-servers to a client, hence breaching the authentication guarantees of Kerberos. It also gives the attacker the keys that the KDC would normally generate to encrypt the service requests of this client, hence defeating confidentiality as well. The discovery of this attack caused the IETF to change the specification of PKINIT and Microsoft to release a Security Update for some Windows operating systems. We discovered this attack as part of an ongoing formal analysis of the Kerberos protocol suite, and we have formally verified several possible fixes to PKINIT--including the one adopted by the IETF--that prevent our attack.
Gerald J. Popek - One of the best experts on this subject based on the ideXlab platform.
-
Resilient self-organizing overlay networks for Security Update delivery
IEEE Journal on Selected Areas in Communications, 2004Co-Authors: Peter Reiher, Gerald J. PopekAbstract:Rapid and widespread dissemination of Security Updates throughout the Internet will be invaluable for many purposes, including sending early-warning signals, updating certificate revocation lists, distributing new virus signatures, etc. Notifying a large number of machines securely, quickly, and reliably is challenging. Such a system must outpace the propagation of threats, handle complexities in a large-scale environment, deal with interruption attacks on dissemination, and also secure itself. Revere addresses these problems by building a large-scale, self-organizing, and resilient overlay network on top of the Internet. We discuss how to secure the dissemination procedure and the overlay network, considering possible attacks and countermeasures. We present experimental measurements of a prototype implementation of Revere gathered using a large-scale-oriented approach. These measurements suggest that Revere can deliver Security Updates at the required scale, speed and resiliency for a reasonable cost.
-
RBone: A Self-Organized Resilient Overlay Network
Advances in Information Security, 2003Co-Authors: Peter Reiher, Gerald J. PopekAbstract:An RBone must be formed and maintained for each different type of Security Update notification to ensure delivery of the needed Security Updates. Composed of Revere nodes and the logical links between them, an RBone is the basis of Security Update dissemination. During Security Update dissemination, Revere forwards Security Updates from one node on the RBone to another along the virtual link between them.
-
Assurance Via Redundancy
Advances in Information Security, 2003Co-Authors: Peter Reiher, Gerald J. PopekAbstract:One of the most critical challenges facing Revere is that of supporting the high availability of Security Update dissemination under various circumstances, including the case where an attacker is trying to corrupt information while in transit. In this chapter we justify the fundamental concept of information assurance via redundancy and discuss general considerations on using redundancy to secure transmissions; we will thus establish that a redundancy mechanism is critical to the success of Revere.
-
A Position Statement: An Approach to Measuring Large-Scale Distributed Systems
2002Co-Authors: Peter Reiher, Gerald J. Popek, Mark D. Yarvis, Geoffrey H. Kuenning, P. Reiher, G. PopekAbstract:Realistic measurement of large-scale distributed systems poses unique challenges. Empirical measurements can capture the true behavior of a real system, but this approach is only feasible when the system is small in scale. Simulation is more scalable, but without running real software, it is difficult for simulation tools to capture all realistic effects. This paper explores a different approach to measuring large-scale distributed systems. We introduce an overloading technique that uses a relatively small number of physical machines but supports the deployment of a distributed system consisting of a large number of logical nodes. We discuss the challenges and advantages of this approach and demonstrate its use to measure the Revere Security Update dissemination system.
Iliano Cervesato - One of the best experts on this subject based on the ideXlab platform.
-
Breaking and fixing public-key Kerberos
Information and Computation, 2008Co-Authors: Iliano Cervesato, Aaron D. Jaggard, Andre Scedrov, Joe-kai Tsay, Christopher WalstadAbstract:AbstractWe report on a man-in-the-middle attack on PKINIT, the public key extension of the widely deployed Kerberos 5 authentication protocol. This flaw allows an attacker to impersonate Kerberos administrative principals (KDC) and end-servers to a client, hence breaching the authentication guarantees of Kerberos. It also gives the attacker the keys that the KDC would normally generate to encrypt the service requests of this client, hence defeating confidentiality as well. The discovery of this attack caused the IETF to change the specification of PKINIT and Microsoft to release a Security Update for some Windows operating systems. We discovered this attack as part of an ongoing formal analysis of the Kerberos protocol suite, and we have formally verified several possible fixes to PKINIT—including the one adopted by the IETF—that prevent our attack as well as other authentication and secrecy properties of Kerberos with PKINIT
-
ASIAN - Breaking and fixing public-key Kerberos
Information & Computation, 2006Co-Authors: Iliano Cervesato, Aaron D. Jaggard, Andre Scedrov, Joe-kai Tsay, Christopher WalstadAbstract:We report on a man-in-the-middle attack on PKINIT, the public key extension of the widely deployed Kerberos 5 authentication protocol. This flaw allows an attacker to impersonate Kerberos administrative principals (KDC) and end-servers to a client, hence breaching the authentication guarantees of Kerberos. It also gives the attacker the keys that the KDC would normally generate to encrypt the service requests of this client, hence defeating confidentiality as well. The discovery of this attack caused the IETF to change the specification of PKINIT and Microsoft to release a Security Update for some Windows operating systems. We discovered this attack as part of an ongoing formal analysis of the Kerberos protocol suite, and we have formally verified several possible fixes to PKINIT--including the one adopted by the IETF--that prevent our attack.
Peter Reiher - One of the best experts on this subject based on the ideXlab platform.
-
Resilient self-organizing overlay networks for Security Update delivery
IEEE Journal on Selected Areas in Communications, 2004Co-Authors: Peter Reiher, Gerald J. PopekAbstract:Rapid and widespread dissemination of Security Updates throughout the Internet will be invaluable for many purposes, including sending early-warning signals, updating certificate revocation lists, distributing new virus signatures, etc. Notifying a large number of machines securely, quickly, and reliably is challenging. Such a system must outpace the propagation of threats, handle complexities in a large-scale environment, deal with interruption attacks on dissemination, and also secure itself. Revere addresses these problems by building a large-scale, self-organizing, and resilient overlay network on top of the Internet. We discuss how to secure the dissemination procedure and the overlay network, considering possible attacks and countermeasures. We present experimental measurements of a prototype implementation of Revere gathered using a large-scale-oriented approach. These measurements suggest that Revere can deliver Security Updates at the required scale, speed and resiliency for a reasonable cost.
-
RBone: A Self-Organized Resilient Overlay Network
Advances in Information Security, 2003Co-Authors: Peter Reiher, Gerald J. PopekAbstract:An RBone must be formed and maintained for each different type of Security Update notification to ensure delivery of the needed Security Updates. Composed of Revere nodes and the logical links between them, an RBone is the basis of Security Update dissemination. During Security Update dissemination, Revere forwards Security Updates from one node on the RBone to another along the virtual link between them.
-
Assurance Via Redundancy
Advances in Information Security, 2003Co-Authors: Peter Reiher, Gerald J. PopekAbstract:One of the most critical challenges facing Revere is that of supporting the high availability of Security Update dissemination under various circumstances, including the case where an attacker is trying to corrupt information while in transit. In this chapter we justify the fundamental concept of information assurance via redundancy and discuss general considerations on using redundancy to secure transmissions; we will thus establish that a redundancy mechanism is critical to the success of Revere.
-
A Position Statement: An Approach to Measuring Large-Scale Distributed Systems
2002Co-Authors: Peter Reiher, Gerald J. Popek, Mark D. Yarvis, Geoffrey H. Kuenning, P. Reiher, G. PopekAbstract:Realistic measurement of large-scale distributed systems poses unique challenges. Empirical measurements can capture the true behavior of a real system, but this approach is only feasible when the system is small in scale. Simulation is more scalable, but without running real software, it is difficult for simulation tools to capture all realistic effects. This paper explores a different approach to measuring large-scale distributed systems. We introduce an overloading technique that uses a relatively small number of physical machines but supports the deployment of a distributed system consisting of a large number of logical nodes. We discuss the challenges and advantages of this approach and demonstrate its use to measure the Revere Security Update dissemination system.
Plattnerbernhard - One of the best experts on this subject based on the ideXlab platform.
-
Firefox (In) Security Update dynamics exposed
Computer Communication Review, 2008Co-Authors: Freistefan, Duebendorferthomas, PlattnerbernhardAbstract:Although there is an increasing trend for attacks against popular Web browsers, only little is known about the actual patch level of daily used Web browsers on a global scale. We conjecture that us...