13th International Workshop on Database and Expert Systems Applications (DEXA'02)
Architectural Defects of the Secure Shell
Aix-en-Provence, France
September 02-September 06
ISBN: 0-7695-1668-8
Although some flaws have been found out in the SSH, the Secure Shell, there is not os much discussion about its architecture or design safety. Therefore, in this paper, considering the SSh's architecture, e.g. the key exchange protocol, the user authentication protocols and its total design of the SSH, we not only discuss the SSH's architectural safety but show some critical flaws for SSH users. For establishing the SSH connection, before the user authentication, the SSH sever and client are exchanging a session key, which can make secure communication. Then, over the secret channel encrypted by the session key, the SSH server are authenticating a user in the SSH client using with a user's password or public key. However, owing to the defects in the SSH protocols and its design, a user can be deprived of its password in the authentication protocol. Moreover, we will show that those who use its public key for authentication are exposed to the menace same as password-oriented users are.
Citation:
Takamichi Saito, Toshiyuki Kito, Kentaro Umesawa, Fumio Mizoguchi, "Architectural Defects of the Secure Shell," dexa, pp.22, 13th International Workshop on Database and Expert Systems Applications (DEXA'02), 2002