[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Carsten Bormann <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
> * Active On-Path Attacker
> * Passive On-Path Attacker

These are great terms.
They describe what an attacker generally can do.
They are not a replacement for MITM.
(Meddler in the middle is the best expansion I have heard so far, see below, but I’ll stick with the non-specific abbreviation now.)

We are not in the phase where terms for this are freely invented.
People in the industry know what a MITM attack is.

RFC 4949 has a really useful definition of MITM:

   $ man-in-the-middle attack
      (I) A form of active wiretapping attack in which the attacker
      intercepts and selectively modifies communicated data to
      masquerade as one or more of the entities involved in a
      communication association. (See: hijack attack, piggyback attack.)

      Tutorial: For example, suppose Alice and Bob try to establish a
      session key by using the Diffie-Hellman-Merkle algorithm without
      data origin authentication service. A "man in the middle" could
      (a) block direct communication between Alice and Bob and then (b)
      masquerade as Alice sending data to Bob, (c) masquerade as Bob
      sending data to Alice, (d) establish separate session keys with
      each of them, and (e) function as a clandestine proxy server
      between them to capture or modify sensitive information that Alice
      and Bob think they are sending only to each other.

Note that this definition specifically describes what MITM is about, and, yes, this definition is way more specific than about what the attacker can do in principle.

I remember doing a quick informal survey of the usage of related terms in research papers at some time in the late 2010s, and there was a clear consensus for MITM, and, incredibly, still for the “man-in-the-middle” expansion.  

For what RFC 4949 describes as MITM, we should stick with MITM, but maybe update with the better expansion.  (For other active on-path attacks, and specifically for describing the capability instead of the attack, we can use the more general term.)

Grüße, Carsten


[Next lecture that involves explaining this concept is scheduled for Tuesday.]

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.