Black-Box Monitoring of Security Protocols, Revision 1

TitleBlack-Box Monitoring of Security Protocols, Revision 1
Publication TypeTechnical Report
Year of Publication2009
AuthorsPironti, A., and J. Jürjens
InstitutionPolitecnico di Torino (Italy), Microsoft Research Cambridge (UK) and Open University (UK)
Abstract

In the challenge of getting provably correct implementations of security protocols, much effort has been recently put into two strategies: model-driven-development to generate new implementations; and verification of the source code of already existing implementations.
However, no approach currently deals with legacy implementations for which no source code is available. This paper presents a formal approach to design and implement monitors that
stop insecure protocol runs executed by legacy implementations, without the need of their source code. We demonstrate the approach at a case study about monitoring a generic SSL server implementation. Our monitoring approach allowed us to detect a flaw in an SSL client
implementation.

AttachmentSize
monitoring1.pdf340.82 KB