Transcription of Under New Management: Practical Attacks on SNMPv3
{{id}} {{{paragraph}}}
Under New Management: Practical Attacks on SNMPv3 Nigel Lawrence and Patrick TraynorGeorgia Tech Information Security Center (GTISC)Georgia Institute of Technology{nlawrence@, monitoring is a necessity for both reducingdowntime and ensuring rapid response in the case of soft-ware or hardware failure. Unfortunately, one of the mostwidely used protocols for monitoring networks, the Sim-ple Network Management Protocol ( SNMPv3 ), does notoffer an acceptable level of confidentiality or integrityfor these services. In this paper, we demonstrate two at-tacks against the most current and secure version of theprotocol with authentication and encryption enabled. Inparticular, we demonstrate that Under reasonable condi-tions, we can read encrypted requests and forge messagesbetween the network monitor and the hosts it Attacks are made possible by an insecure discoverymechanism, which allows an adversary capable of com-promising a single network host to set the keys used bythe security functions.}
done via SNMP, the serial port, or a web interface. Of these options, only SNMP allows for scalable configura-tion management accross a diverse group of devices. For example, a managed LAN switch can be configured with features such as port specific Quality of Service (QoS)
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}