• DocumentCode
    3022678
  • Title

    Plaintext Recovery Attacks against SSH

  • Author

    Albrecht, Martin R. ; Paterson, Kenneth G. ; Watson, Gaven J.

  • Author_Institution
    Inf. Security Group, Univ. of London, Egham, UK
  • fYear
    2009
  • fDate
    17-20 May 2009
  • Firstpage
    16
  • Lastpage
    26
  • Abstract
    This paper presents a variety of plaintext-recovering attacks against SSH. We implemented a proof of concept of our attacks against OpenSSH, where we can verifiably recover 14 bits of plaintext from an arbitrary block of ciphertext with probability 2-14 and 32 bits of plaintext from an arbitrary block of ciphertext with probability 2-18. These attacks assume the default configuration of a 128-bit block cipher operating in CBC mode. The paper explains why a combination of flaws in the basic design of SSH leads implementations such as OpenSSH to be open to our attacks, why current provable security results for SSH do not cover our attacks, and how the attacks can be prevented in practice.
  • Keywords
    cryptography; protocols; OpenSSH; ciphertext arbitrary block; plaintext recovery attacks; secure protocol suites; Cryptographic protocols; Cryptography; Data mining; Information security; Internet; Privacy; SSH; attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2009 30th IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-0-7695-3633-0
  • Type

    conf

  • DOI
    10.1109/SP.2009.5
  • Filename
    5207634