Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Ecryption Cracking Tools |
|---|---|
| Date: | Thu, 27 Oct 2005 15:51:58 -0700 |
I make it up as I go along...
FC
On Oct 27, 2005, at 3:24 PM, Austin Murkland wrote:
Well i understand it would be difficult...just not how difficult or if it would be impossible...any suggestions on source material i could brush up on to get a better idea of how to develop such a thing?
-Austin Murkland
Fred Cohen wrote:
Alas it is far harder than it might seem. Shannon tells us that the unicity distance is only 2.4 times the key size for English and attempts to create multiple valid looking decryptions for multiples of that is very hard. A better approach is to provide lots of excess data so that parts can be decrypted with different approaches, but this is also problematic in its way. Another approach is what I used in DTK (Deception ToolKit). We created false password files that could be cracked and used them to tell how good the attackers were based on how long it took them to break what.
FC
On Oct 26, 2005, at 11:54 AM, Austin Murkland wrote:
I had a thought. With all the talk of honeypot systems, and services. Wouldn't it make more sense to have a Crypto cipher that took into account the possibility of being brute forced and provided one or more sets of logical pseudo-information when cracked, but only the real information when actually cracked/ authenticated?
at it's simplest level, have one set of data that is the actual message, and another set of data that is something that could be the actual message. Security would increase given the number of sets of pseudo-data included in the encrypted message...so if it were cracked using brute force, how would they know it was actually what they were looking for. My understanding is that brute force relies on there being only one possible true answer for it to work. While this is still true with this idea, there also exists multiple pseudo-answers that provide information that may or may not look like the actual answer.
This could be combined with further honeypot systems and ids to both make it difficult to get to the correct system, and to immediately be notified that someone is actively trying to brute force your encryption and it's time to change keys. E.g. a password is encrypted using this method, and 30 sets of pseudo- data is included in the encrypted password. lets say when properly brute forced it provides 20 deadend passwords that just don't work, 10 passwords that lead to honeypots systems, and 1 real password that gets them, or the authenticated user in. if they try any of the 30, before the 1, an IDS could be easily configured to ban their IP, alert the admin, or even run a script that does all this and then changes the key.
i don't know if this is a new idea or not.. i guess it would be HoneyPot Encryption... ?
Austin Murkland
john@gmail.com wrote:
Use a Vernam cipher. If you do it right it will be fun to watch them try to crack it.
-- This communication is confidential to the parties it is intended to serve --
Security Posture securityposture.com tel/fax
University of New Haven unhca.com 925-454-0171
Fred Cohen & Associates all.net 572 Leona Drive
Security Management Partners policygeeks.com Livermore, CA 94550
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Wireless security question..., Marty |
|---|---|
| Next by Date: | RE: Odd SonicWall behavior, Jason Harris |
| Previous by Thread: | Re: Ecryption Cracking Tools, Austin Murkland |
| Next by Thread: | RE: Ecryption Cracking Tools, Chris Hunhoff |
| Indexes: | [Date] [Thread] [Top] [All Lists] |