Gartner warns of 'proliferation of new attack tools'
Gartner warns of 'proliferation of new attack tools'
R E L A T E D   C O N T E N T
ADVERTISEMENT

Gartner warns of crypto bug attack tools

Weakness in security algorithms 'means trouble', says analyst

Robert Jaques, vnunet.com 24 May 2005
ADVERTISEMENT

The recently discovered bug allowing timing attacks against cryptographic algorithms could allow hackers to measure the behaviour of cryptographic software to reveal information about its keys.

Industry experts have warned that this will "inevitability result in the proliferation of new attack tools".

Analyst firm Gartner said that the attacks against cryptographic algorithms, discovered by Canadian researcher Colin Percival, could allow hackers to extract sensitive data by creating a parallel thread to measure cache activity in a cryptographic thread.

The attack does not reflect a security weakness in processor hyper-threading, but rather a weakness in the security algorithms exposed by Percival's ingenious timing attack, according to Gartner.

"The opportunities to use this attack seem narrow, because there are other, simpler ways to access keys running on the same machine. But history suggests that unaddressed security flaws usually mean trouble," said Martin Reynolds, vice president at Gartner's Dataquest division.

"Vendors of cryptographic code must address this weakness as a priority, by either affirming that their code is safe or correcting the flaw."

However, Reynolds added that disabling hyper-threading is not an effective solution to the problem. Vulnerable code must be corrected, or cryptographic processes must be run in protected environments.

The analyst advises against keeping intermediate results, keys or passwords in memory. Algorithms should delete secret bits as soon as they are no longer needed.

"Password entries should be checked against hashes after initialisation. Intermediate results should be written over as soon as possible, rather than left in memory," said Reynolds.

"These approaches defend against spy processes that peer into memory, and against searching of hibernation and paging files, as well as unallocated memory."

According to Gartner, enterprises should identify areas where cryptographic software could represent a risk and ask their vendor to certify that they have secured code against the exploit.

"Gartner has identified at least one security package that keeps passwords in memory, which means that the password is propagated into the hibernation and system paging files and is subject to trivial memory scanning," Reynolds warned.

See also:

Government Accountability Office warns of failure to secure vital internet infrastructureCountry not ready to fend off electronic attack  01 Jun 2005
Effective IT security infrastructure deemed key to UK's competitivenessBCS survey reveals difficulty in justifying infrastructure investment  24 May 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOEGrass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Server Support Analyst (Citrix skills required) - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & ... more >
Boston Spa, Leeds, United Kingdom | The British Library
 Application Specialist - £26,196 - £31,348 - Boston SpaExcellent benefits including a civil service pension scheme + online product discounts + childcare discounts + onsite nursery + wide range of social clubs + great staff ... more >
More job opportunities