PROTOCOL VULNERABILITIES IN PRACTICE: CAUSES, MODELING AND AUTOMATIC DETECTION *
Bogdan Groza, Marius Minea, Marius Cristea, Pal-Stefan Murvay, M. Iacob · 2012
Starting from practical scenarios we underline that the most relevant security vulnerabilities in practice come from weak protocol design or implementation flaws rather than from weak or flawed cryptography. In particular, we outline security vulnerabilities in several kinds of scenarios starting from well explored fields such as computer networks to less explored ones from the automotive industry and control systems. Some of the security flaws that we discuss are already known while others are new and have been subject of our previous research. Finally, we emphasize that to assure good security, focus should be on assuring correct implementations and proper tools for automatic verification of services. Key words: protocol, vulnerability, automatic verification. 1.