A type flaw attack on a security protocol is an attack where a field that was originally intended to have one type is subsequently interpreted as having another type. In the paper, we describe some typical examples of type flaw attack and give a type flaw attack that was found on the GDOI protocol. We then analysize the limitations of recent tagging technique of preventing type flaw attack. Finally, a method against type flaw attack by checking the length of message is proposed.
Index Terms:
security protocol, type flaw attack, GDOI
Citation:
Juan Wang, Jingwei Zhang, Huanguo Zhang, "Type Flaw Attacks and Prevention in Security Protocols," snpd, pp.340-343, 2008 Ninth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing, 2008