The Experts below are selected from a list of 66 Experts worldwide ranked by ideXlab platform
Tomáš Rosa - One of the best experts on this subject based on the ideXlab platform.
-
Bypassing Passkey Authentication in Bluetooth Low Energy
2015Co-Authors: Tomáš RosaAbstract:This memo describes certain new cryptographic weakness of the passkey-based pairing of Bluetooth LE (BLE or BTLE, also known as Bluetooth Smart; as one prefers). The vulnerability discussed here extends the set of possible Attacking scenarios that were already elaborated before by Mike Ryan in [4]. Instead of the passive Sniffing Attack on pairing secrets, we show how a fraudulent Responder [1] can gracefully bypass the passkey authentication, despite it being possibly based on even one-time generated PIN. Such an active Attack may become handy in situation where passive Sniffing of correct pairing cannot be employed – for instance, because of the original Responder device being out of reach or otherwise unwilling to pair again. Or, we may already want to actively impersonate the peripheral device to inject some data into e.g. iPhone Apps from Attacker’s keyboard, perform MITM, etc. Since the Attack runs on the Security Manager layer [1], it can reuse a lot of the existing network stack that is already in place for this approach. This namely concerns everything bellow Host Controller Interface (HCI) [1]. Actually, the whole procedure starting with the authentication bypass and continuing to data injection (which would be a regular communication anyway) can be done using a general Bluetooth 4.0 Smart Ready USB dongle via HCI commands. Furthermore, we shall perhaps emphasize the Attack we present here would be possible even if there already was the yet-awaited ephemeral Diffie-Hellman key agreement employed in BLE as, for instance, in Bluetooth BR/EDR Secur
-
Bypassing Passkey Authentication in Bluetooth Low Energy
2013Co-Authors: Tomáš RosaAbstract:This memo describes certain new cryptographic weakness of the passkey-based pairing of Bluetooth LE (BLE or BTLE, also known as Bluetooth Smart; as one prefers). The vulnerability discussed here extends the set of possible Attacking scenarios that were already elaborated before by Mike Ryan in [4]. Instead of the passive Sniffing Attack on pairing secrets, we show how a fraudulent Responder can gracefully bypass passkey authentication, despite it being possibly based on even one-time generated PIN. Such an active Attack may become handy in situation where passive Sniffing of correct pairing cannot be employed – for instance, because the original Responder device is out of reach or otherwise unwilling to pair again. Or, we may already want to actively impersonate the peripheral device to inject some data into e.g. iPhone Apps, perform MITM, etc. Since the Attack runs on the Security Manager layer, it can reuse a lot of the existing network stack that is already in place for this approach. This namely concerns everything bellow HCI [1]. Actually, the whole procedure starting with the authentication bypass and continuing to data injection (which would be a regular communication anyway) can be done using a general Bluetooth 4.0 Smart Ready USB dongle via HCI commands. Furthermore, we shall perhaps emphasize the Attack we present here would be possible even if there already was the yet-awaited ephemeral Diffie-Hellman key agreement employed in BLE as, for instance, in Bluetooth BR/EDR Secur
Sapna Chaudhary - One of the best experts on this subject based on the ideXlab platform.
-
Content Sniffing Attack Detection in Client and Server Side: A Survey
2014Co-Authors: Bhupendra Singh Thakur, Sapna ChaudharyAbstract:In today’s environment we cannot think about internet. It has the interface of client and server. After analysing several research studies, we conclude that the communication between client and server may suffer from several security concerns like Denial of Service (DoS) Attack, Content Sniffing Attack and Replay Attack. In this paper we mainly concentrate on content Sniffing Attack. We survey several traditional techniques on content Sniffing Attack and major the advantage and disadvantages. We also focus on finding the better security provision which can be applied during data communication through client and server. Our main aim of this paper is to find the outcomes which can better detect the content Sniffing Attack in client and server side
Gajendra Singh - One of the best experts on this subject based on the ideXlab platform.
-
Survey and Analysis of Client Side Detection of Content Sniffing Attack
2013Co-Authors: Animesh Dubey, Ravindra Gupta, Gajendra SinghAbstract:From the last few years, the Attacks based on web portals have caused significant harm to users. Many of these Attacks occur through the exploitations of common security vulnerabilities in web-based programs. Given that, mitigation of these Attacks is extremely crucial to reduce some of the harmful consequences. Web-based applications contain vulnerabilities that can be exploited by Attackers at client-side (browser) without the victim"s (browser user"s) knowledge. Our work is intended to some exploitation due to the presence of security vulnerabilities in web applications while performing seemingly benign functionalities at the client-side. In this paper we survey the aspects of content Sniffing Attack mainly on client side and analyses how the control should be monitor from the server side after Attack.
Bhupendra Singh Thakur - One of the best experts on this subject based on the ideXlab platform.
-
Content Sniffing Attack Detection in Client and Server Side: A Survey
2014Co-Authors: Bhupendra Singh Thakur, Sapna ChaudharyAbstract:In today’s environment we cannot think about internet. It has the interface of client and server. After analysing several research studies, we conclude that the communication between client and server may suffer from several security concerns like Denial of Service (DoS) Attack, Content Sniffing Attack and Replay Attack. In this paper we mainly concentrate on content Sniffing Attack. We survey several traditional techniques on content Sniffing Attack and major the advantage and disadvantages. We also focus on finding the better security provision which can be applied during data communication through client and server. Our main aim of this paper is to find the outcomes which can better detect the content Sniffing Attack in client and server side
Ruslan Kozak - One of the best experts on this subject based on the ideXlab platform.
-
The etalon models of linguistic variables for Sniffing-Attack detection
2017 9th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 2017Co-Authors: Mikołaj Karpiński, Anna Korchenko, Pavlo Vikulov, Anatoliy Balyk, Roman Kochan, Ruslan KozakAbstract:Intensive development of information systems has led to an increase in malicious software, which is associated with the emergence of new types of cyber Attacks. Expanding impact of cyber Attacks aimed at a variety of resources information system initiates creation of special countermeasures that can be effective in the emergence of new types of threats from unknown or ill-defined properties. There are enough effective developments, are used to solve problems of cyber Attacks identification, for example, the method of linguistic etalons formation for the detection of intrusion systems, which does not disclose the mechanism of the formation of etalons settings for Sniffing Attacks. In this work, was developed etalons model of linguistic variables to detect Sniffing Attacks, which is due to assess the state of the information system and the process of forming the parameters of etalons will allow to formalize the process of obtaining the parameters of etalons for a given linguistic variables in specific environment in solving Attacks detection tasks on computer systems.