Automated state-machine-based analysis of hostname verification in ipsec implementations

3Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

Owing to the advent and rapid development of Internet communication technology, network security protocols with cryptography as their core have gradually become an important means of ensuring secure commu-nications. Among numerous security protocols, certificate authentication is a common method of identity au-thentication, and hostname verification is a critical but easily neglected process in certificate authentication. Hostname verification validates the identity of a remote target by checking whether the hostname of the communication partner matches any name in the X.509 certificate. Notably, errors in hostname verification may cause security problems with regard to identity authentication. In this study, we use a model-learning method to conduct security testing for hostname verification in internet protocol security (IPsec). This method can analyze the problems entailed in implementing hostname verification in IPsec by effectively inferring the deterministic finite automaton model that can describe the matching situation between the certificate subject name and the hostname for different rules. We analyze two popular IPsec implementations, Strongswan and Libreswan, and find five violations. We use some of these violations to conduct actual attack tests on the IP-sec implementation. The results show that under certain conditions, attackers can use these flaws to carry out identity impersonation attacks and man-in-the-middle attacks.

Cite

CITATION STYLE

APA

Guo, J., Gu, C., Chen, X., Lu, S., & Wei, F. (2021). Automated state-machine-based analysis of hostname verification in ipsec implementations. Information Technology and Control, 50(3), 570–587. https://doi.org/10.5755/j01.itc.50.3.27844

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free