Secure public instant messaging
Mohammad Mannan · 2005
Canada de reproduire, publier, archiver, sauvegarder, conserver, transmettre au public par telecommunication ou par I'lnternet, preter, distribuer et vendre des theses partout dans le monde, a des fins commerciales ou autres, sur support microforme, papier, electronique et/ou autres formats.i * i Canada R ep ro d u ced with p erm ission o f th e copyright ow ner.Further reproduction prohibited w ithout perm ission.list feature to track users' availability in AOL Instant Messenger (AIM) [3].How 1 R ep ro d u ced with p erm ission o f th e copyright ow ner.Further reproduction prohibited w ithout perm ission.1.1.Introdu ction 2 ever, the recent rise in popularity of consumer IM services has been phenomenal (e.g.see [89]).Starting as a casual application, mainly used by young adults and college students, IM systems now connect even naval operations (over 300 US Navy warships are connected via an IM service) and various customer services [33].There are many public domain IM services.The most popular include AIM [3], ICQ [66], MSN Messenger (Windows Messenger in Windows XP) [102], and Yahoo!Messenger (YIM) [188].We focus on these messaging networks and their default clients.1There are also many third-party2 clients th at interact on these networks.We discuss both the third-party and default clients in terms of the security risks associated with them.The basic protocols currently used in public IM systems are open to many security threats (see Chapter 3 and 4).Security techniques, e.g.TLS/SSL connections or digital certificates, used in corporate IM systems are inadequate to address these threats (see below). M otivation .IM differs from many other Internet applications because of its near real-time nature of user interactions, e.g.online presence notification and instant messages.Conse quently, many security mechanisms designed for other Internet applications (e.g.web browser, email) are inadequate for IM.Despite the immense popularity of IM sys tems (both in the consumer and business world), security issues related to IM have largely been ignored by the security research community.To our knowledge, there exists no complete security protocol suite in the literature specifically tailored for password-based IM systems.1By default clients we m ean th e IM clients p rovided by public IM service providers (e.g.MSN M essenger).2B y third-party clients we refer to clients (e.g.G aim [125], T rillian [32], IM Secure [192]) w hich in te ract w ith th e existing m a jo r IM n etw orks, an d secu rity -en h an ced IM p ro d u cts (e.g.Yahoo! Business M essenger [187]).