Gartner warns of 'proliferation of new attack tools'
Gartner warns of 'proliferation of new attack tools'
R E L A T E D   C O N T E N T
ADVERTISEMENT

Gartner warns of crypto bug attack tools

Weakness in security algorithms 'means trouble', says analyst

Robert Jaques, vnunet.com 24 May 2005
ADVERTISEMENT

The recently discovered bug allowing timing attacks against cryptographic algorithms could allow hackers to measure the behaviour of cryptographic software to reveal information about its keys.

Industry experts have warned that this will "inevitability result in the proliferation of new attack tools".

Analyst firm Gartner said that the attacks against cryptographic algorithms, discovered by Canadian researcher Colin Percival, could allow hackers to extract sensitive data by creating a parallel thread to measure cache activity in a cryptographic thread.

The attack does not reflect a security weakness in processor hyper-threading, but rather a weakness in the security algorithms exposed by Percival's ingenious timing attack, according to Gartner.

"The opportunities to use this attack seem narrow, because there are other, simpler ways to access keys running on the same machine. But history suggests that unaddressed security flaws usually mean trouble," said Martin Reynolds, vice president at Gartner's Dataquest division.

"Vendors of cryptographic code must address this weakness as a priority, by either affirming that their code is safe or correcting the flaw."

However, Reynolds added that disabling hyper-threading is not an effective solution to the problem. Vulnerable code must be corrected, or cryptographic processes must be run in protected environments.

The analyst advises against keeping intermediate results, keys or passwords in memory. Algorithms should delete secret bits as soon as they are no longer needed.

"Password entries should be checked against hashes after initialisation. Intermediate results should be written over as soon as possible, rather than left in memory," said Reynolds.

"These approaches defend against spy processes that peer into memory, and against searching of hibernation and paging files, as well as unallocated memory."

According to Gartner, enterprises should identify areas where cryptographic software could represent a risk and ask their vendor to certify that they have secured code against the exploit.

"Gartner has identified at least one security package that keeps passwords in memory, which means that the password is propagated into the hibernation and system paging files and is subject to trivial memory scanning," Reynolds warned.

See also:

Government Accountability Office warns of failure to secure vital internet infrastructureCountry not ready to fend off electronic attack  01 Jun 2005
Effective IT security infrastructure deemed key to UK's competitivenessBCS survey reveals difficulty in justifying infrastructure investment  24 May 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | MI5 Security Service
Software Developer/SQL Specialists Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis and ... more >
London, United Kingdom | London School of Economics
  IT Services -Systems Specialist  (Business Continuity), Salary: £38,212 - £44,264 p.a. 2 years fixed-term LSE is a cosmopolitan community in the centre of London focusing on the study of the social sciences. IT Services ... more >
Leeds, United Kingdom | NHS Connecting Health
  Project Manager, Leeds, up to £53k  NHS Connecting for Health is an agency of the Department of Health supporting the NHS to deliver better, safer care to patients, by bringing in new computer systems ... more >
Maidstone, United Kingdom | Kent Police
  Assistant Forensic Computer Analyst - Police Headquarters, Maidstone, £20,164 - £23,632 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit ... more >
More job opportunities