论文标题

Chronos-ntp的互联网中可证明安全系统的陷阱

Pitfalls of Provably Secure Systems in Internet The Case of Chronos-NTP

论文作者

Jeitner, Philipp, Shulman, Haya, Waidner, Michael

论文摘要

网络时间协议(NTP)在Internet中扮演的关键作用导致了多项努力,以确保其免受时间转移攻击。最新提出的提案是通过计时攻击者对NTP的安全性提高,这似乎是最有前途的攻击者,并且是IETF的标准化轨道。在这项工作中,我们展示了针对Chronos增强NTP客户的分数攻击。弱链接是Chronos的中心安全功能:使用DNS的服务器池生成机制。我们表明,DNS的不安全感允许颠覆计时的安全性,使针对Chronos-NTP的时移攻击甚至比针对普通NTP的攻击更容易。

The critical role that Network Time Protocol (NTP) plays in the Internet led to multiple efforts to secure it against time-shifting attacks. A recent proposal for enhancing the security of NTP with Chronos against on-path attackers seems the most promising one and is on a standardisation track of the IETF. In this work we demonstrate off-path attacks against Chronos enhanced NTP clients. The weak link is a central security feature of Chronos: The server pool generation mechanism using DNS. We show that the insecurity of DNS allows to subvert the security of Chronos making the time-shifting attacks against Chronos-NTP even easier than attacks against plain NTP.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源