Clarifying straight replays and forced delays

  • Authors:
  • Taekyoung Kwon;Jooseok Song

  • Affiliations:
  • Department of Computer Science, Yonsei University, Seoul 120-749, Korea;Department of Computer Science, Yonsei University, Seoul 120-749, Korea

  • Venue:
  • ACM SIGOPS Operating Systems Review
  • Year:
  • 1999

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper clarifies straight replays which are one of replay attacks but have been somewhat misunderstood. There are various kinds of replay attacks on authentication protocols but most of the formal methods are not capable of detecting them because a replayed message may have appropriate data and structure for the protocols. [1] classified them and proposed their taxonomy that is useful for readily determining the effectiveness of some replay countermeasures and the appropriateness of analysis techniques for replays. [1] urges that any kinds of replay attacks are classified in the taxonomy. Among those classified attacks, however, straight replay attacks are ambiguous to be distinguished from forced delays which are really not regarded as replays.