|Title||Identifying Potential Type Confusion in Authenticated Messages|
|Publication Type||Conference Paper|
|Year of Publication||2002|
|Conference Name||Workshop on Foundations of Computer Security|
|Conference Location||Copenhagen, Denmark|
A type confusion attack is one in which a principal accepts data of one type as data of another. Although it has been shown by Heather et al. that there are simple formatting conventions that will guarantee that protocols are free from simple type confusions in which fields of one type are substituted for fields of another, it is not clear how well they defend against more complex attacks, or against attacks arising from interaction with protocols that are formatted according to different conventions. In this paper we show how type confusion attacks can arise in realistic situations even when the types are explicitly defined in at least some of the messages, using examples from our recent analysis of the Group Domain of Interpretation Protocol. We then develop a formal model of types that can capture potential ambiguity of type notation, and outline a procedure for determining whether or not the types of two messages can be confused. We also discuss some open issues.
|NRL Publication Release Number|| |