Zen and the Art of Breaking Security - Part II

There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.

provided by: 
Originally published at Internet.com


By Razvan Peteanu for SecurityPortal -----------------------------------

Today we will continue our journey into the less explored ways to break security. Part one has explained what Zen has to do with the topic.

There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.

Since computing equipment uses electrical power to function, manipulating the voltage becomes an obvious target. A handy but coarse attack would be to blow the circuit up into smoke by applying the 110/220V voltage to it. Not elegant and a bit dangerous, but perfectly valid in the real world if this is what it takes to access a bank safe.

This is the very reason security systems should have a fail-safe operation: the failure of the protection mechanism should leave the rest of the system in a secure state. A power lock should keep the door locked in the event of a power outage, and a firewall should be designed so that if its software crashes, all traffic is blocked between its interfaces...

Read article at Internet.com site
Related Articles
- URL, URL, Little Do We Know Thee
URLs have associated security implications. "Interesting" ways of using them have been known by spammers for a while, but now the Microsoft Knowledge Base spoof and the February of Crypto-Gram have made the Internet community more aware of what URLs can do.
- Email Filtering: The Real Deal
- E-commerce Security: VeriSign
- Managing Outgoing Viruses
- Zen and the Art of Breaking Security - Part I
- An Unbreakable Code?
- Why Firewalls?
- Ending Trust in Certificates
- Encrypting an Access Database
- FTP Attacks
Regional Articles
- Zen and the Art of Breaking Security - Part II Alabama
- Zen and the Art of Breaking Security - Part II Alaska
- Zen and the Art of Breaking Security - Part II Arizona
- Zen and the Art of Breaking Security - Part II Arkansas
- Zen and the Art of Breaking Security - Part II California
- Zen and the Art of Breaking Security - Part II Colorado
- Zen and the Art of Breaking Security - Part II Connecticut
- Zen and the Art of Breaking Security - Part II DC
- Zen and the Art of Breaking Security - Part II Delaware
- Zen and the Art of Breaking Security - Part II Florida
- Zen and the Art of Breaking Security - Part II Georgia
- Zen and the Art of Breaking Security - Part II Hawaii
- Zen and the Art of Breaking Security - Part II Idaho
- Zen and the Art of Breaking Security - Part II Illinois
- Zen and the Art of Breaking Security - Part II Indiana
- Zen and the Art of Breaking Security - Part II Iowa
- Zen and the Art of Breaking Security - Part II Kansas
- Zen and the Art of Breaking Security - Part II Kentucky
- Zen and the Art of Breaking Security - Part II Louisiana
- Zen and the Art of Breaking Security - Part II Maine
- Zen and the Art of Breaking Security - Part II Maryland
- Zen and the Art of Breaking Security - Part II Massachusetts
- Zen and the Art of Breaking Security - Part II Michigan
- Zen and the Art of Breaking Security - Part II Minnesota
- Zen and the Art of Breaking Security - Part II Mississippi
- Zen and the Art of Breaking Security - Part II Missouri
- Zen and the Art of Breaking Security - Part II Montana
- Zen and the Art of Breaking Security - Part II Nebraska
- Zen and the Art of Breaking Security - Part II Nevada
- Zen and the Art of Breaking Security - Part II New Hampshire
- Zen and the Art of Breaking Security - Part II New Jersey
- Zen and the Art of Breaking Security - Part II New Mexico
- Zen and the Art of Breaking Security - Part II New York
- Zen and the Art of Breaking Security - Part II North Carolina
- Zen and the Art of Breaking Security - Part II North Dakota
- Zen and the Art of Breaking Security - Part II Ohio
- Zen and the Art of Breaking Security - Part II Oklahoma
- Zen and the Art of Breaking Security - Part II Oregon
- Zen and the Art of Breaking Security - Part II Pennsylvania
- Zen and the Art of Breaking Security - Part II Rhode Island
- Zen and the Art of Breaking Security - Part II South Carolina
- Zen and the Art of Breaking Security - Part II South Dakota
- Zen and the Art of Breaking Security - Part II Tennessee
- Zen and the Art of Breaking Security - Part II Texas
- Zen and the Art of Breaking Security - Part II Utah
- Zen and the Art of Breaking Security - Part II Vermont
- Zen and the Art of Breaking Security - Part II Virginia
- Zen and the Art of Breaking Security - Part II Washington
- Zen and the Art of Breaking Security - Part II West Virginia
- Zen and the Art of Breaking Security - Part II Wisconsin
- Zen and the Art of Breaking Security - Part II Wyoming
Related Articles
- URL, URL, Little Do We Know Thee
URLs have associated security implications. "Interesting" ways of using them have been known by spammers for a while, but now the Microsoft Knowledge Base spoof and the February of Crypto-Gram have made the Internet community more aware of what URLs can do.
- Email Filtering: The Real Deal
- E-commerce Security: VeriSign
- Managing Outgoing Viruses
- Zen and the Art of Breaking Security - Part I
- An Unbreakable Code?
- Why Firewalls?
- Ending Trust in Certificates
- Encrypting an Access Database
- FTP Attacks

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML