The Deviation Attack: A Novel Denial-of-Service Attack Against IKEv2 - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Pré-Publication, Document De Travail Année : 2018

The Deviation Attack: A Novel Denial-of-Service Attack Against IKEv2

Résumé

In previous analyses, IKEv2 has been shown to possess two authentication vulnerabilities that were considered not exploitable. In this paper, we analyze the protocol specification using the Spin model checker, and prove that in fact the first vulnerability does not exist. In addition, we show that the second vulnerability is exploitable by designing and implementing a novel slow Denial-of-Service attack, which we name the Deviation Attack. We explain the attack's requirements, discuss possible countermeasures and propose a modification of the protocol that we prove eliminates the vulnerability.
Fichier principal
Vignette du fichier
main.pdf (617.77 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01980276 , version 1 (25-01-2019)
hal-01980276 , version 2 (22-10-2019)

Identifiants

  • HAL Id : hal-01980276 , version 1

Citer

Tristan Ninet, Axel Legay, Romaric Maillard, Louis-Marie Traonouez, Olivier Zendra. The Deviation Attack: A Novel Denial-of-Service Attack Against IKEv2. 2018. ⟨hal-01980276v1⟩

Relations

462 Consultations
1198 Téléchargements

Partager

Gmail Facebook X LinkedIn More