Attacking the IPsec Standards in Encryption-only Configurations
Generate an AI Snapshot to get a quick, structured summary of this paper.
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
New attacks which break any RFC- compliant implementation of IPsec making use of encryption-only ESP in tunnel mode are described, which are ciphertext-only and need only the capability to eavesdrop on ESP-encrypted traffic and to inject traffic into the network.
Abstract
We describe new attacks which break any RFC- compliant implementation of IPsec making use of encryption-only ESP in tunnel mode. The new attacks are both efficient and realistic: they are ciphertext-only and need only the capability to eavesdrop on ESP-encrypted traffic and to inject traffic into the network. We report on our experiences in applying the attacks to a variety of implementations of IPsec.
