Perspectives: improving SSH-style host authentication with multi-path probing

ATC'08 USENIX 2008 Annual Technical Conference on Annual Technical Conference(2008)

引用 353|浏览3
暂无评分
摘要
The popularity of "Trust-on-first-use" (Tofu) authentication, used by SSH and HTTPS with self-signed certificates, demonstrates significant demand for host authentication that is low-cost and simple to deploy. While Tofu-based applications are a clear improvement over completely insecure protocols, they can leave users vulnerable to even simple network attacks. Our system, PERSPECTIVES, thwarts many of these attacks by using a collection of "notary" hosts that observes a server's public key via multiple network vantage points (detecting localized attacks) and keeps a record of the server's key over time (recognizing short-lived attacks). Clients can download these records on-demand and compare them against an unauthenticated key, detecting many common attacks. PERSPECTIVES explores a promising part of the host authentication design space: Trust-on-first-use applications gain significant attack robustness without sacrificing their ease-of-use. We also analyze the security provided by PERSPECTIVES and describe our experience building and deploying a publicly available implementation.
更多
查看译文
关键词
host authentication,host authentication design space,public key,unauthenticated key,Trust-on-first-use application,multiple network vantage point,significant attack robustness,significant demand,simple network attack,Tofu-based application,SSH-style host authentication
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要