TOWARDS SECURE NETWORK COMMUNICATIONS WITH CLIENTS HAVING CRYPTOGRAPHICALLY ATTESTABLE INTEGRITY
Dan Luţaş, Sándor Lukács, Raul Tosa, Andrei Luțaș · 2013
In a client-server communication, the server side must trust the client before releases confidential data or accepts commands received from the client. While industry best practices and considerable amount of research focus on secure credential authentication, we stress that this is at most a deceptive effort, providing only a false sense of security. We underline the sharp contradiction between state-of-the-art industry wide practices and the security that researchers campaign for, with special focus on online banking solutions. We present a brief review of a wide range of cyberattack techniques used today to perform large scale identity theft, financial fraud or espionage. We believe that current approaches, including inside-OS security solutions or relying only on credential authentication are outdated, and an industry wide shift is needed to provide trustable, integrity attested clients. Our solution is created around a type 1 bare-metal hypervisor, relying on hardware-enforced technologies to provide strong isolation between a secure operating environment on the clients and a possibly compromised OS. Blending an easily deployable solution with remote cryptographic identity attestation support, we believe that our proposal carries a significant value, both from security point of view and market applicability. In order to support a proper evaluation of the strength and weaknesses of the solution, we also present a comprehensive review of various remaining attack techniques and strategies.