SSL and TCP

SSL and TCP

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SSL and TCP pvsnmp 09-25-2006
Posted by on September 25, 2006, 11:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello all,

I was reading the paper "Analysis of the IPSec Key Exchange Standard"
by Radia Perlman and Charlie Kaufman.
http://sec.femto.org/wetice-2001/papers/radia-paper.pdf
In Section 2.2 they have written the following:

"There is a problem in operating above TCP. Since TCP will not be
participating in the cryptography, it will have no way of noticing if
malicious data is inserted into the packet stream. TCP will acknowledge
such data and send it up to SSL, which will discard it because the
integrity check will indicate the data is bogus, but there is no way
for SSL to tell TCP to accept the real data at this point. When the
real data arrives, it will look to TCP like duplicate data, since it
will have the same sequence numbers as the bogus data, so TCP will
discard it. So in theory, IPSec's approach of cryptographically
protecting each packet independently is a better approach. "


When TCP has already acknowledged the data which is malicious according
to SSL, how will a retransmission by SSL cause the remote TCP to use
the same sequence number and cause the first end point's TCP to discard
it?

Thanks and Regards,
Prashant


Posted by on September 26, 2006, 12:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
http://groups.google.com/group/comp.protocols.tcp-ip/browse_thread/thread/8c98fbe8688bd41e/7413aead257b8824#7413aead257b8824



The site map in XML format XML site map

Contact Us | Privacy Policy