login

Attacking the IPsec Standards in Encryption-only Configurations

Published 1 May 2007
Jean Paul Degabriele, Kenneth G. Paterson
Citations56

TL;DR

New attacks which break any RFC- compliant implementation of IPsec making use of encryption-only ESP in tunnel mode are described, which are ciphertext-only and need only the capability to eavesdrop on ESP-encrypted traffic and to inject traffic into the network.

Abstract

We describe new attacks which break any RFC- compliant implementation of IPsec making use of encryption-only ESP in tunnel mode. The new attacks are both efficient and realistic: they are ciphertext-only and need only the capability to eavesdrop on ESP-encrypted traffic and to inject traffic into the network. We report on our experiences in applying the attacks to a variety of implementations of IPsec.

Keywords

Computer ScienceEngineering