Malice versus AN.ON: possible risks of missing replay and integrity protection

  • Authors:
  • Benedikt Westermann;Dogan Kesdogan

  • Affiliations:
  • Q2S, NTNU, Trondheim, Norway;Q2S, NTNU, Trondheim, Norway

  • Venue:
  • FC'11 Proceedings of the 15th international conference on Financial Cryptography and Data Security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we investigate the impact of missing replay protection as well as missing integrity protection concerning a local attacker in AN.ON. AN.ON is a low latency anonymity network mostly used to anonymize web traffic. We demonstrate that both protection mechanisms are important by presenting two attacks that become feasible as soon as the mechanisms are missing. We mount both attacks on the AN.ON network which neither implements replay protection nor integrity protection yet.