A Systematic Analysis of the Juniper Dual EC Incident
Stephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried, Shaanan Cohney, Matthew Green, Nadia Heninger, Ralf-Philipp Weinmann, Eric Rescorla, Hovav Shacham
摘要
In December 2015, Juniper Networks announced multiple security vulnerabilities stemming from unauthorized code in ScreenOS, the operating system for their NetScreen VPN routers. The more sophisticated of these vulnerabilities was a passive VPN decryption capability, enabled by a change to one of the elliptic curve points used by the Dual EC pseudorandom number generator.
In this paper, we describe the results of a full independent analysis of the ScreenOS randomness and VPN key establishment protocol subsystems, which we carried out in response to this incident. While Dual EC is known to be insecure against an attacker who can choose the elliptic curve parameters, Juniper had claimed in 2013 that ScreenOS included countermeasures against this type of attack. We find that, contrary to Juniper's public statements, the ScreenOS VPN implementation has been vulnerable since 2008 to passive exploitation by an attacker who selects the Dual EC curve point. This vulnerability arises due to apparent flaws in Juniper's countermeasures as well as a cluster of changes that were all introduced concurrently with the inclusion of Dual EC in a single 2008 release. We demonstrate the vulnerability on a real NetScreen device by modifying the firmware to install our own parameters, and we show that it is possible to passively decrypt an individual VPN session in isolation without observing any other network traffic. We investigate the possibility of passively fingerprinting ScreenOS implementations in the wild. This incident is an important example of how guidelines for random number generation, engineering, and validation can fail in practice.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet 等S&P 2021 · 被引用 169 次
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon 等CCS 2019 · 被引用 159 次
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 被引用 63 次
- Verified Correctness and Security of mbedTLS HMAC-DRBGKatherine Q. Ye, Matthew Green, Naphat Sanguansin, Lennart Beringer 等CCS 2017 · 被引用 59 次
相关 Paper
- Practical State Recovery Attacks against Legacy RNG ImplementationsShaanan N. Cohney, Matthew D. Green, Nadia HeningerCCS 2018 · 被引用 21 次
- Open to a fault: On the passive compromise of TLS keys via transient errorsGeorge Arnold Sullivan, Jackson Sippe, Nadia Heninger, Eric WustrowUSENIX Security 2022
- The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA ModuliMatús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec 等CCS 2017 · 被引用 147 次
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer 等CCS 2016 · 被引用 196 次
- The Dangers of Key Reuse: Practical Attacks on IPsec IKEDennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak 等USENIX Security 2018 · 被引用 41 次
