Automated analysis of security-sensitive protocols

Oct 25, 2005

The sheer number and variety of security protocols for Internet applications under development makes it difficult to be sure that any one protocol is 100 per cent secure from attack. Now an automated tool can systematically validate these security-sensitive protocols and applications.

“The AVISPA software tool enables a security protocol designer to input the protocol and the language he/she wishes to use, then feeds back information on this protocol including any known bugs or security weaknesses,” says Professor Alessandro Armando of the University of Genoa’s Artificial Intelligence Laboratory (DIST) and coordinator of the IST programme-backed Future and Emerging Technologies project AVISPA. “Previously such protocol designers had no automated support to help them in their design role – that is the purpose of the AVISPA tool."

Secure protocols are a vital element in carrying out safe online interactions between a user’s Web browser and a company Web server, for example a bank’s Web server in an online banking application. Though such protocols might look simple, they can often be extremely difficult to get absolutely right, such as with no bugs or weaknesses in the protocol.

Armando quotes the classic example of the Needham-Schroeder public-key protocol, which was first published in 1978 as a means of mutual authentication between two parties using public-key cryptography. The protocol was eventually found to be vulnerable to simple attacks in 1996, eighteen years later!

AVISPA participants aimed to develop a push-button, industrial-strength technology for the analysis of such security-sensitive Internet protocols and applications. The project finished in July 2005 with the release of the AVISPA tool, which is a simple software application that runs on a PC or via a Web interface. It can be accessed online, and offers both a Basic and an Expert mode.

The consortium partners believe that this new tool will help speed the development of the next generation of security protocols, and improve their security in the process.

Project partner Siemens has already discovered a weakness in one of its own protocols using the tool, and has revised the protocol and issued a new patent accordingly. The partners have started collaborating with SAP for continuing the analysis of more complex security-sensitive applications under future research projects.

Source: IST Results

Explore further: Microsoft challenging US on overseas data

add to favorites email to friend print save as pdf

Related Stories

Designing exascale computers

Jul 23, 2014

"Imagine a heart surgeon operating to repair a blocked coronary artery. Someday soon, the surgeon might run a detailed computer simulation of blood flowing through the patient's arteries, showing how millions ...

Biodistribution of carbon nanotubes in the body

Jul 04, 2014

Having perfected an isotope labeling method allowing extremely sensitive detection of carbon nanotubes in living organisms1, CEA and CNRS researchers have looked at what happens to nanotubes after one year inside an animal. ...

Recommended for you

Microsoft challenging US on overseas data

2 hours ago

In a case closely watched by the tech sector, Microsoft will challenge Thursday a US court order requiring it to give prosecutors electronic mail content associated with an overseas server.

Facebook's Internet.org expands in Zambia

2 hours ago

(AP)—Facebook's Internet.org project is taking another step toward its goal of bringing the Internet to people who are not yet online with an app launching Thursday in Zambia.

Sony surprises with first quarter profit

2 hours ago

(AP)—Sony Corp. reported a surprise eightfold jump in quarterly profit Thursday as sales got a perk from a cheap yen and its bottom line was helped by gains from selling buildings and its stake in a video-game maker.

Samsung profit falls as smartphone sales slow

2 hours ago

(AP)—Samsung Electronics Co. reported a bigger-than-expected fall in second quarter profit on Thursday and said it was uncertain if earnings from its handset business would improve in the current quarter.

User comments : 0