Revising Security Protocols against Network Attacks based on Event-B

Junxiang Zhu, Xiang Zhang · 2020

Verifying that a security protocol is immune to a given kind of network attack is usually an important but challenging task. Even we know a security protocol is vulnerable to some kind of attacks, revising it to disable that attack is also a non-trivial work. This paper proposes a generic framework based on Event-B and Rodin platform to guide the revising of a security protocol so that an known successful attack can no longer take place upon the revised protocol. The attack scenario is reflected with an abstract model and is developed to capture the behaviours from both the protocol and the attacker. The vulnerability of the protocol to the attack is verified by showing that the model is a refinement of the abstract model. Then the revision of the protocol can be modeled by first separating the protocol behavior from the model and refining it solely. The security of the revised protocol can be verified by showing that the composed model with the attack is no longer a refinement of the abstract model. We demonstrated this approach on the revision of the 4-way handshake protocol of Wi-Fi Protected Access2(WPA2) that is exposed to Key Reinstallation Attacks(KRACK).

Read the paper · More papers on PaperTik