Zen and the Art of Breaking Security - Part II DC

There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.

Local Companies

Events by Andre Wells
(202) 518-6908
5704 16th St NW
Washington, DC
na
571-337-7104
1417 NST NW #403
washington, DC

provided by: 
Originally published at Internet.com


By Razvan Peteanu for SecurityPortal -----------------------------------

Today we will continue our journey into the less explored ways to break security. Part one has explained what Zen has to do with the topic.

There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.

Since computing equipment uses electrical power to function, manipulating the voltage becomes an obvious target. A handy but coarse attack would be to blow the circuit up into smoke by applying the 110/220V voltage to it. Not elegant and a bit dangerous, but perfectly valid in the real world if this is what it takes to access a bank safe.

This is the very reason security systems should have a fail-safe operation: the failure of the protection mechanism should leave the rest of the system in a secure state. A power lock should keep the door locked in the event of a power outage, and a firewall should be designed so that if its software crashes, all traffic is blocked between its interfaces...

Read article at Internet.com site

Featured Local Company

na

571-337-7104
1417 NST NW #403
washington, DC

Related Articles
- Ending Trust in Certificates DC
There are hundreds of thousands of certificates floating around. The whole premise of certificates is that multiple parties trust a central certificate authority. This form of security and verification is not without issues.
- FTP Attacks DC
- An Unbreakable Code? DC
- E-commerce Security: VeriSign DC
- Encrypting an Access Database DC
- URL, URL, Little Do We Know Thee DC
- Zen and the Art of Breaking Security - Part I DC
- Email Filtering: The Real Deal DC
- Why Firewalls? DC
- Managing Outgoing Viruses DC
Related Articles
- Ending Trust in Certificates DC
There are hundreds of thousands of certificates floating around. The whole premise of certificates is that multiple parties trust a central certificate authority. This form of security and verification is not without issues.
- FTP Attacks DC
- An Unbreakable Code? DC
- E-commerce Security: VeriSign DC
- Encrypting an Access Database DC
- URL, URL, Little Do We Know Thee DC
- Zen and the Art of Breaking Security - Part I DC
- Email Filtering: The Real Deal DC
- Why Firewalls? DC
- Managing Outgoing Viruses DC

Topics: 
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML