About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Gartner warns of 'proliferation of new attack tools'
Gartner warns of 'proliferation of new attack tools'
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Gartner warns of crypto bug attack tools

Weakness in security algorithms 'means trouble', says analyst

Robert Jaques, vnunet.com 24 May 2005
ADVERTISEMENT

The recently discovered bug allowing timing attacks against cryptographic algorithms could allow hackers to measure the behaviour of cryptographic software to reveal information about its keys.

Industry experts have warned that this will "inevitability result in the proliferation of new attack tools".

Analyst firm Gartner said that the attacks against cryptographic algorithms, discovered by Canadian researcher Colin Percival, could allow hackers to extract sensitive data by creating a parallel thread to measure cache activity in a cryptographic thread.

The attack does not reflect a security weakness in processor hyper-threading, but rather a weakness in the security algorithms exposed by Percival's ingenious timing attack, according to Gartner.

"The opportunities to use this attack seem narrow, because there are other, simpler ways to access keys running on the same machine. But history suggests that unaddressed security flaws usually mean trouble," said Martin Reynolds, vice president at Gartner's Dataquest division.

"Vendors of cryptographic code must address this weakness as a priority, by either affirming that their code is safe or correcting the flaw."

However, Reynolds added that disabling hyper-threading is not an effective solution to the problem. Vulnerable code must be corrected, or cryptographic processes must be run in protected environments.

The analyst advises against keeping intermediate results, keys or passwords in memory. Algorithms should delete secret bits as soon as they are no longer needed.

"Password entries should be checked against hashes after initialisation. Intermediate results should be written over as soon as possible, rather than left in memory," said Reynolds.

"These approaches defend against spy processes that peer into memory, and against searching of hibernation and paging files, as well as unallocated memory."

According to Gartner, enterprises should identify areas where cryptographic software could represent a risk and ask their vendor to certify that they have secured code against the exploit.

"Gartner has identified at least one security package that keeps passwords in memory, which means that the password is propagated into the hibernation and system paging files and is subject to trivial memory scanning," Reynolds warned.

See also:

Government Accountability Office warns of failure to secure vital internet infrastructureCountry not ready to fend off electronic attack  01 Jun 2005
Effective IT security infrastructure deemed key to UK's competitivenessBCS survey reveals difficulty in justifying infrastructure investment  24 May 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Leek Wootton, United Kingdom | Warwickshire Police
 IT Business Analyst - Leek Wootton, Warwickshire - £29,112 - £31,491 PA - 37 hrs per week   Everyone who works for Warwickshire Police helps to protect our communities from harm. Work with us and ... more >
United Kingdom | Sussex HIS via Acertus Ltd
Business Development and Partnership Director - £62,337 to £77,179 plus benefits Any Sussex HIS location by agreement  The Sussex HIS was formed in mid 2004 through the merging of all IT services from all Trusts ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
London, United Kingdom | MI5
Programme Managers - Project Managers -Project Support Staff - Competitive Salary + Excellent Benefits - London   Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT