• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Liu, Fanbao (Liu, Fanbao.) | Xie, Tao (Xie, Tao.) | Feng, Yumeng (Feng, Yumeng.) | Feng, Dengguo (Feng, Dengguo.)

收录:

EI Scopus SCIE

摘要:

Point-to-Point Protocol over Ethernet (PPPoE) is a network protocol for encapsulating PPP frames inside Ethernet frames. It is widely used by commercial Internet service providers to provide Internet surfing for customers who pay bills. In this paper, we analyze the security of PPPoE network. We find that we can easily collect information about both the peers and the PPPoE authentication servers. We can use such information to recover the peer's authentication password by silently impersonating the server, which is undetectable in the network. We impersonate the server in the peers' LAN and get their passwords by hijacking the peers' PPPoE connections and negotiating for using the Password Authentication Protocol (PAP). We further propose an efficient password recovery attack against the Challenge-Handshake Authentication Protocol (CHAP). We first recover the length of the used password through on-line queries, based on the weakness of MD5 input pre-processing. Then, we crack the known-length password off-line, using the probabilistic context-free grammars. We point out that PPPoE cannot be used anymore until all of the weak authentication protocols including PAP, CHAP, and Microsoft CHAP are abolished right now and replaced with more secure Extensible Authentication Protocols. Copyright (c) 2012 John Wiley & Sons, Ltd.

关键词:

authentication protocol CHAP PAP password recovery PPP PPPoE

作者机构:

  • [ 1 ] [Liu, Fanbao]Natl Univ Def Technol, Sch Comp, Changsha 410073, Hunan, Peoples R China
  • [ 2 ] [Xie, Tao]Natl Univ Def Technol, Ctr Soft Comp & Cryptol, Changsha 410073, Hunan, Peoples R China
  • [ 3 ] [Feng, Yumeng]Beijing Univ Technol, Sch Comp, Beijing 100124, Peoples R China
  • [ 4 ] [Feng, Dengguo]Chinese Acad Sci, State Key Lab Informat Secur, Beijing 100124, Peoples R China

通讯作者信息:

  • [Liu, Fanbao]Natl Univ Def Technol, Sch Comp, Changsha 410073, Hunan, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

SECURITY AND COMMUNICATION NETWORKS

ISSN: 1939-0114

年份: 2012

期: 10

卷: 5

页码: 1159-1168

ESI学科: COMPUTER SCIENCE;

ESI高被引阀值:137

JCR分区:4

中科院分区:4

被引次数:

WoS核心集被引频次: 3

SCOPUS被引频次: 8

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 3

归属院系:

在线人数/总访问数:431/2893716
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司