The Experts below are selected from a list of 66 Experts worldwide ranked by ideXlab platform

Tomáš Rosa - One of the best experts on this subject based on the ideXlab platform.

  • Bypassing Passkey Authentication in Bluetooth Low Energy
    2015
    Co-Authors: Tomáš Rosa
    Abstract:

    This memo describes certain new cryptographic weakness of the passkey-based pairing of Bluetooth LE (BLE or BTLE, also known as Bluetooth Smart; as one prefers). The vulnerability discussed here extends the set of possible Attacking scenarios that were already elaborated before by Mike Ryan in [4]. Instead of the passive Sniffing Attack on pairing secrets, we show how a fraudulent Responder [1] can gracefully bypass the passkey authentication, despite it being possibly based on even one-time generated PIN. Such an active Attack may become handy in situation where passive Sniffing of correct pairing cannot be employed – for instance, because of the original Responder device being out of reach or otherwise unwilling to pair again. Or, we may already want to actively impersonate the peripheral device to inject some data into e.g. iPhone Apps from Attacker’s keyboard, perform MITM, etc. Since the Attack runs on the Security Manager layer [1], it can reuse a lot of the existing network stack that is already in place for this approach. This namely concerns everything bellow Host Controller Interface (HCI) [1]. Actually, the whole procedure starting with the authentication bypass and continuing to data injection (which would be a regular communication anyway) can be done using a general Bluetooth 4.0 Smart Ready USB dongle via HCI commands. Furthermore, we shall perhaps emphasize the Attack we present here would be possible even if there already was the yet-awaited ephemeral Diffie-Hellman key agreement employed in BLE as, for instance, in Bluetooth BR/EDR Secur

  • Bypassing Passkey Authentication in Bluetooth Low Energy
    2013
    Co-Authors: Tomáš Rosa
    Abstract:

    This memo describes certain new cryptographic weakness of the passkey-based pairing of Bluetooth LE (BLE or BTLE, also known as Bluetooth Smart; as one prefers). The vulnerability discussed here extends the set of possible Attacking scenarios that were already elaborated before by Mike Ryan in [4]. Instead of the passive Sniffing Attack on pairing secrets, we show how a fraudulent Responder can gracefully bypass passkey authentication, despite it being possibly based on even one-time generated PIN. Such an active Attack may become handy in situation where passive Sniffing of correct pairing cannot be employed – for instance, because the original Responder device is out of reach or otherwise unwilling to pair again. Or, we may already want to actively impersonate the peripheral device to inject some data into e.g. iPhone Apps, perform MITM, etc. Since the Attack runs on the Security Manager layer, it can reuse a lot of the existing network stack that is already in place for this approach. This namely concerns everything bellow HCI [1]. Actually, the whole procedure starting with the authentication bypass and continuing to data injection (which would be a regular communication anyway) can be done using a general Bluetooth 4.0 Smart Ready USB dongle via HCI commands. Furthermore, we shall perhaps emphasize the Attack we present here would be possible even if there already was the yet-awaited ephemeral Diffie-Hellman key agreement employed in BLE as, for instance, in Bluetooth BR/EDR Secur

Sapna Chaudhary - One of the best experts on this subject based on the ideXlab platform.

  • Content Sniffing Attack Detection in Client and Server Side: A Survey
    2014
    Co-Authors: Bhupendra Singh Thakur, Sapna Chaudhary
    Abstract:

    In today’s environment we cannot think about internet. It has the interface of client and server. After analysing several research studies, we conclude that the communication between client and server may suffer from several security concerns like Denial of Service (DoS) Attack, Content Sniffing Attack and Replay Attack. In this paper we mainly concentrate on content Sniffing Attack. We survey several traditional techniques on content Sniffing Attack and major the advantage and disadvantages. We also focus on finding the better security provision which can be applied during data communication through client and server. Our main aim of this paper is to find the outcomes which can better detect the content Sniffing Attack in client and server side

Gajendra Singh - One of the best experts on this subject based on the ideXlab platform.

  • Survey and Analysis of Client Side Detection of Content Sniffing Attack
    2013
    Co-Authors: Animesh Dubey, Ravindra Gupta, Gajendra Singh
    Abstract:

    From the last few years, the Attacks based on web portals have caused significant harm to users. Many of these Attacks occur through the exploitations of common security vulnerabilities in web-based programs. Given that, mitigation of these Attacks is extremely crucial to reduce some of the harmful consequences. Web-based applications contain vulnerabilities that can be exploited by Attackers at client-side (browser) without the victim"s (browser user"s) knowledge. Our work is intended to some exploitation due to the presence of security vulnerabilities in web applications while performing seemingly benign functionalities at the client-side. In this paper we survey the aspects of content Sniffing Attack mainly on client side and analyses how the control should be monitor from the server side after Attack.

Bhupendra Singh Thakur - One of the best experts on this subject based on the ideXlab platform.

  • Content Sniffing Attack Detection in Client and Server Side: A Survey
    2014
    Co-Authors: Bhupendra Singh Thakur, Sapna Chaudhary
    Abstract:

    In today’s environment we cannot think about internet. It has the interface of client and server. After analysing several research studies, we conclude that the communication between client and server may suffer from several security concerns like Denial of Service (DoS) Attack, Content Sniffing Attack and Replay Attack. In this paper we mainly concentrate on content Sniffing Attack. We survey several traditional techniques on content Sniffing Attack and major the advantage and disadvantages. We also focus on finding the better security provision which can be applied during data communication through client and server. Our main aim of this paper is to find the outcomes which can better detect the content Sniffing Attack in client and server side

Ruslan Kozak - One of the best experts on this subject based on the ideXlab platform.

  • The etalon models of linguistic variables for Sniffing-Attack detection
    2017 9th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 2017
    Co-Authors: Mikołaj Karpiński, Anna Korchenko, Pavlo Vikulov, Anatoliy Balyk, Roman Kochan, Ruslan Kozak
    Abstract:

    Intensive development of information systems has led to an increase in malicious software, which is associated with the emergence of new types of cyber Attacks. Expanding impact of cyber Attacks aimed at a variety of resources information system initiates creation of special countermeasures that can be effective in the emergence of new types of threats from unknown or ill-defined properties. There are enough effective developments, are used to solve problems of cyber Attacks identification, for example, the method of linguistic etalons formation for the detection of intrusion systems, which does not disclose the mechanism of the formation of etalons settings for Sniffing Attacks. In this work, was developed etalons model of linguistic variables to detect Sniffing Attacks, which is due to assess the state of the information system and the process of forming the parameters of etalons will allow to formalize the process of obtaining the parameters of etalons for a given linguistic variables in specific environment in solving Attacks detection tasks on computer systems.