DocumentCode
3022678
Title
Plaintext Recovery Attacks against SSH
Author
Albrecht, Martin R. ; Paterson, Kenneth G. ; Watson, Gaven J.
Author_Institution
Inf. Security Group, Univ. of London, Egham, UK
fYear
2009
fDate
17-20 May 2009
Firstpage
16
Lastpage
26
Abstract
This paper presents a variety of plaintext-recovering attacks against SSH. We implemented a proof of concept of our attacks against OpenSSH, where we can verifiably recover 14 bits of plaintext from an arbitrary block of ciphertext with probability 2-14 and 32 bits of plaintext from an arbitrary block of ciphertext with probability 2-18. These attacks assume the default configuration of a 128-bit block cipher operating in CBC mode. The paper explains why a combination of flaws in the basic design of SSH leads implementations such as OpenSSH to be open to our attacks, why current provable security results for SSH do not cover our attacks, and how the attacks can be prevented in practice.
Keywords
cryptography; protocols; OpenSSH; ciphertext arbitrary block; plaintext recovery attacks; secure protocol suites; Cryptographic protocols; Cryptography; Data mining; Information security; Internet; Privacy; SSH; attack;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy, 2009 30th IEEE Symposium on
Conference_Location
Berkeley, CA
ISSN
1081-6011
Print_ISBN
978-0-7695-3633-0
Type
conf
DOI
10.1109/SP.2009.5
Filename
5207634
Link To Document