[saag] Re: On path Active Attackers, and Meddlers in the M iddle
Carsten Bormann <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
> * Active On-Path Attacker
> * Passive On-Path Attacker
These are great terms.
They describe what an attacker generally can do.
They are not a replacement for MITM.
(Meddler in the middle is the best expansion I have heard so far, see below, but I’ll stick with the non-specific abbreviation now.)
We are not in the phase where terms for this are freely invented.
People in the industry know what a MITM attack is.
RFC 4949 has a really useful definition of MITM:
$ man-in-the-middle attack
(I) A form of active wiretapping attack in which the attacker
intercepts and selectively modifies communicated data to
masquerade as one or more of the entities involved in a
communication association. (See: hijack attack, piggyback attack.)
Tutorial: For example, suppose Alice and Bob try to establish a
session key by using the Diffie-Hellman-Merkle algorithm without
data origin authentication service. A "man in the middle" could
(a) block direct communication between Alice and Bob and then (b)
masquerade as Alice sending data to Bob, (c) masquerade as Bob
sending data to Alice, (d) establish separate session keys with
each of them, and (e) function as a clandestine proxy server
between them to capture or modify sensitive information that Alice
and Bob think they are sending only to each other.
Note that this definition specifically describes what MITM is about, and, yes, this definition is way more specific than about what the attacker can do in principle.
I remember doing a quick informal survey of the usage of related terms in research papers at some time in the late 2010s, and there was a clear consensus for MITM, and, incredibly, still for the “man-in-the-middle” expansion.
For what RFC 4949 describes as MITM, we should stick with MITM, but maybe update with the better expansion. (For other active on-path attacks, and specifically for describing the capability instead of the attack, we can use the more general term.)
Grüße, Carsten
[Next lecture that involves explaining this concept is scheduled for Tuesday.]
_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]