一种针对分组密码软件的 APT 后门及其防范

An Wang, Yong Yin Dong, Lie Huang Zhu, Yu Zhang, Yao Ling Ding*

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

摘要

With the rapid development of computer technology and information technology, software is used everywhere. Attackers can make use of software backdoors to gain important information and resources, causing severe problems and losses. There are contradictions between the concealment and powerful function of software backdoors. Long codes and complex functionalities bring obvious features of the backdoor. This paper proposes a feasible backdoor injection scheme on the block cipher software. The proposed method is based on differential fault analysis, reverse engineering, and advanced persistent threat. By employing fault ciphertexts from active backdoor and correct ciphertexts from non-active backdoor, it is possible to recover the whole DES key by differential fault analysis. The characteristics of this backdoor include strong concealment, easy to operate, can cause big harm, etc. So, this backdoor can be used as a means of advanced persistent threat. Finally, countermeasures for this type of backdoor are given, and the problems of backdoor injection and defense are dialectically discussed.

投稿的翻译标题APT backdoor for block cipher software and its countermeasures
源语言繁体中文
页(从-至)65-75
页数11
期刊Journal of Cryptologic Research
8
1
DOI
出版状态已出版 - 25 2月 2021

关键词

  • Advanced persistent threat
  • DES algorithm
  • Differential fault analysis
  • Reverse analysis
  • Software backdoor

指纹

探究 '一种针对分组密码软件的 APT 后门及其防范' 的科研主题。它们共同构成独一无二的指纹。

引用此