论文标题
在消息转发协议中进行建模代理攻击攻击
Modelling Agent-Skipping Attacks in Message Forwarding Protocols
论文作者
论文摘要
消息转发协议是一组代理处理消息传输的协议。每个代理都将收到的消息转发给链中的下一个代理。例如,TLS Middlebox在TLS中充当中介剂,添加了诸如过滤或压缩数据之类的功能。在这样的协议中,攻击者可能会尝试绕过一个或多个中介代理。这样的代理攻击攻击可以违反协议的安全要求。在符号设置中,使用MultiSet重写模型,我们构建了此类路径协议的综合框架。特别是,我们介绍了与路径完整性有关的一组安全目标:信息忠实地通过参与者以启动代理人打算的顺序传播的概念。我们对几种此类协议进行安全分析,突出了对现代协议的关键攻击。
Message forwarding protocols are protocols in which a chain of agents handles transmission of a message. Each agent forwards the received message to the next agent in the chain. For example, TLS middleboxes act as intermediary agents in TLS, adding functionality such as filtering or compressing data. In such protocols, an attacker may attempt to bypass one or more intermediary agents. Such an agent-skipping attack can the violate security requirements of the protocol. Using the multiset rewriting model in the symbolic setting, we construct a comprehensive framework of such path protocols. In particular, we introduce a set of security goals related to path integrity: the notion that a message faithfully travels through participants in the order intended by the initiating agent. We perform a security analysis of several such protocols, highlighting key attacks on modern protocols.