•  
  • Home
  • Unix hosting server management $ 29/Month
  • Seo Optimization
  • Privacy
  • Sitemap

Severe Vulnerabilities Discovered in Software to Protect Internet Routing

[ad_1]

Frankfurt and Darmstadt, April 2024

A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.

The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor – effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.

RPKI is a relatively new standard. Today, about 50% of the Internet’s network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.

The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnerabilities-in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from
https://github.com/rp-cure/rp-cure.

The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe’s most prominent cybersecurity research center and Germany’s leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.

Press Contact: Mrs. Cornelia Reitz, cornelia.reitz@athene-center.de

[ad_2]
Source link


Share This Post

  • Facebook
  • Twitter
  • Google Plus
  • Pinterest

Related Posts

Jackery Explorer 2000 Plus expandable power station with independently solar-chargeable battery packs for on-site energy

Jackery Explorer 2000 Plus expandable power station with independently solar-chargeable battery packs for on-site energy

July 26, 2023
THE COLOURFUL HISTORY OF THE HUMBLE PAINTBRUSH SHEDS LIGHT ON OUR PREVAILING RELATIONSHIP WITH ART AND NATURE IN THIS NEW BOOK, SET FOR PRE-CHRISTMAS LAUNCH

THE COLOURFUL HISTORY OF THE HUMBLE PAINTBRUSH SHEDS LIGHT ON OUR PREVAILING RELATIONSHIP WITH ART AND NATURE IN THIS NEW BOOK, SET FOR PRE-CHRISTMAS LAUNCH

October 30, 2023
New release charity single for Mental health support and suicide prevention charity – Bearded Fishermen

New release charity single for Mental health support and suicide prevention charity – Bearded Fishermen

December 7, 2023

Menu

  • A Solution for Small Breweries to Generate Extra Income Using Existing Equipment
  • Uncover the Ultimate Solution for Automating Your Pinterest Pins
  • Assessing the Impact of Web Hosting AR Augmented Reality Experiences
  • Ecommerce Web Hosting With Shopping Cart
  • The Leanest Launch: Distillery Edition
  • Web Hosting Drupal Websites
  • The world of alcohol-free Spirits
  • Reviewing Aromhuset’s Zero Sugar Raspberry: Supreme Quality and No Off-taste?
  • Web Hosting Running and Fitness Blogs
  • Reviewing Aromhuset Zero Sugar Lemon Lime: A Leading Contender?
  • Web Hosting For Online Fitness Coaching
  • Unveiling the Delightful Flavors of Aromhuset Off-Taste Free Soda Concentrate
  • Aromhuset’s Raspberry Drops: An Intensity Flavor Review
  • Discover the benefits of a healthier lifestyle by using alcohol-free Spirits from the UK: Your Path to wellness begins now!
  • Zero Sugar Indian Tonic Soda: A Premium Choice?
  • Aromhuset Off-Taste Aromhuset Off-Taste Free Zero Sugarpop Soda Syrup: The Perfect Addition to Your Healthy Lifestyle
  • Unlocking Peace: Alcohol-Free Spirits and Mental Health in the EU Make a Change Now!
  • Explore the bursting of Citrusy Flavors in Aromhuset Zero Sugar Concentrate Orange Soda Syrup
  • Explore the delicious, sugar-free Aromhuset Blood Orange Soda syrup for a refreshing beverage without any off-tastes
  • Web Hosting Redis Database
  • A Broad Audit of IVW-videomaker
  • Let us Consider about TheDomainSnooper from thedomainsnooper.com
  • Privacy
  • Prosper Profit Opinion From A member since 4 Years
  • Sitemap
  • Home
  • Unix hosting server management $ 29/Month
  • Seo Optimization
  • Privacy
  • Sitemap

Powered by myunixhosting.com