How to break XML encryption – automatically

Dennis Kupser, Christian Mainka, Jörg Schwenk, Juraj Somorovsky · 2015

In the recent years, XML Encryption became a target of several new attacks [19, 18, 17]. These attacks belong to the family of adaptive chosen-ciphertext attacks, and al-low an adversary to decrypt symmetric and asymmetric XML ciphertexts, without knowing the secret keys. In order to protect XML Encryption implementations, the World Wide Web Consortium (W3C) published an up-dated version of the standard. Unfortunately, most of the current XML Encryption implementations do not support the newest XML En-cryption specification and offer different XML Security configurations to protect confidentiality of the exchanged messages. Resulting from the attack complexity, evalu-ation of the security configuration correctness becomes tedious and error prone. Validation of the applied coun-termeasures can typically be made with numerous XML messages provoking incorrect behavior by decrypting XML content. Up to now, this validation was only man-ually possible. In this paper, we systematically analyze the chosen-ciphertext attacks on XML Encryption and design an al-gorithm to perform a vulnerability scan on arbitrary en-crypted XML messages. The algorithm can automati-cally detect a vulnerability and exploit it to retrieve the plaintext of a message protected by XML Encryption. To assess practicability of our approach, we implemented an open source attack plugin for Web Service attacking tool called WS-Attacker. With the plugin, we discovered new security problems in four out of five analyzed Web Service implementations, including IBM Datapower or Apache CXF. ∗This is the full version of the paper with same title that was

Read the paper · More papers on PaperTik