DocumentCode :
2781082
Title :
Identifying andTesting for Insecure Paths in Cryptographic Protocol Implementations
Author :
Jayaram, K.R.
Author_Institution :
Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN
Volume :
2
fYear :
2006
fDate :
17-21 Sept. 2006
Firstpage :
368
Lastpage :
369
Abstract :
Cryptographic protocols, which are also referred to as security protocols are used to process, store and transfer increasing volumes of information on our financial networks, health networks, and even our library systems, not to mention our conventional communication systems and our networked systems of personal and corporate computers. Users should be able to justifiably rely on their implementations to process, store, and communicate sensitive information securely. Testing is indispensable even when a security protocol is formally verified because most formal verification techniques only guarantee the correctness of the design, under certain assumptions. More importantly, no guarantees about the implementation are provided. A mathematical proof that an implementation of a security protocol conforms to its specifications is usually not feasible because it would require complicated formal semantics of the language in which it is written and the environment in which the protocol runs (the operating system and hardware)
Keywords :
cryptography; formal verification; protocols; IPSec vulnerabiltiy; Kerberos implementations; OpenSSL library; SSL 3.0; buffer overflows; cryptographic protocols; financial networks; formal semantics; formal verification; health networks; information security; insecure SSL 2.0 protocol; insecure path identification; insecure path testing; key distribution server; library systems; man-in-the middle attack; race conditions; security protocol; security protocols; security vulnerabilities; Communication system security; Computer networks; Computer security; Cryptographic protocols; Formal verification; Hardware; Information security; Libraries; Operating systems; Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference, 2006. COMPSAC '06. 30th Annual International
Conference_Location :
Chicago, IL
ISSN :
0730-3157
Print_ISBN :
0-7695-2655-1
Type :
conf
DOI :
10.1109/COMPSAC.2006.133
Filename :
4020199
Link To Document :
بازگشت