Padlock
The CPNI has raised questions over the security of the TCP/IP system
R E L A T E D   C O N T E N T
ADVERTISEMENT

Brits blast TCP/IP security

Report questions safety at the heart of the web

Shaun Nichols in San Francisco, vnunet.com 21 Aug 2008
ADVERTISEMENT

A report from a top UK government defence body is calling into question the security of the basic internet protocol.

The TCP/IP protocol is the basic function used by computers to communicate with outside networks. First adopted in 1983, the TCP/IP system is widely credited with enabling the creation of the internet as we know it.

The same protocol that enables the internet, however, may also be leaving it at risk, according to the Centre for Protection of the National Infrastructure (CPNI)

The company notes that many of the same techniques first used to link up the Arpanet network in 1983 are still in use today by the modern-day internet, and not all of them are secure.

"While many textbooks and articles have created the myth that the Internet Protocols were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the Arpanet, " read the introduction to the report.

"As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications. "

The CPNI noted that over the years vulnerabilities have emerged in everything from the handling of headers to dealing with fragments of code and reassembling data.

Even when those problems are patched, the CPNI pointed out that the fixes are not always approved or recommended by the Internet Engineering Task Force.

"In many cases vendors have implemented quick 'fixes' to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability," the report read.

"As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past."

See also:

GCHQElements of national infrastructure continue to be attacked electronically, says government  08 Aug 2008
Windows for WorkgroupsAnother operating system bites the dust  11 Jul 2008
Vint Cerf'Father of the internet' receives prestigious awards  18 Apr 2008
Vint CerfDecades before we fully understand the impact, says Vint Cerf  04 Dec 2007
Arpanet scientist warns of coming network crunch  29 Oct 2007

All Enterprise Security Technology
Tags: Internet, Security, Infrastructure, Tcp-ip, Internet

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities