Verify-Pro: A Framework for Server Authentication using Communication Protocol Dialects

被引:2
|
作者
Gogineni, Kailash [1 ]
Mei, Yongsheng [1 ]
Venkataramani, Guru [1 ]
Lan, Tian [1 ]
机构
[1] George Washington Univ, Dept Elect & Comp Engn, Washington, DC 20052 USA
关键词
Program customization; Protocol dialects; Deep learning; Authentication;
D O I
10.1109/MILCOM55135.2022.10017649
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Customizing program binary and communication features is a commonly adopted strategy to counter network security threats like session hijacking, context confusion, and impersonation attacks. A potential attacker may have enough time to launch an attack targeting these vulnerabilities by rerouting the target request to a malicious server or hijacking the traffic. This paper presents a novel system Verify-Pro, a framework for server authentication using communication protocol dialects by customizing the communication features, enforcing continuous authentication, detecting the adversary, and preventing sensitive information leakage. Specifically, we leverage a machine learning approach (pre-trained neural network model) on both client and server machines to trigger a specific dialect that dynamically changes for each request (e.g., get filename in FTP). Then, a decision tree algorithm is developed to automatically detect the adversary and terminate the entire session if the message is from an adversary. We implement a prototype of VerifyPro and evaluate its practicality on standard communication protocol: FTP (File Transfer Protocol) and present a case study of the internet of things protocol MQTT (Message Queuing Telemetry Transport). Our experimental results show that by sending misleading information through the message packets from an attacker at the application layer, it is possible for the recipient to identify if the sender is genuine or a spoofed one, with a negligible overhead of < 1%.
引用
收藏
页数:8
相关论文
共 49 条
  • [1] Verify-Pro: A Framework for Server Authentication using Communication Protocol Dialects
    2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2022,
  • [2] Can you speak my dialect?: A Framework for Server Authentication using Communication Protocol Dialects
    Gogineni, Kailash
    Mei, Yongsheng
    Venkataramani, Guru
    Lan, Tian
    arXiv, 2022,
  • [3] An efficient anonymous authentication protocol in multiple server communication networks (EAAM)
    An Braeken
    Pardeep Kumar
    Madhusanka Liyanage
    Ta Thi Kim Hue
    The Journal of Supercomputing, 2018, 74 : 1695 - 1714
  • [4] An efficient anonymous authentication protocol in multiple server communication networks (EAAM)
    Braeken, An
    Kumar, Pardeep
    Liyanage, Madhusanka
    Ta Thi Kim Hue
    JOURNAL OF SUPERCOMPUTING, 2018, 74 (04): : 1695 - 1714
  • [5] A secure and improved multi server authentication protocol using fuzzy commitment
    Rehman, Hafeez Ur
    Ghani, Anwar
    Chaudhry, Shehzad Ashraf
    Alsharif, Mohammed H.
    Nabipour, Narjes
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (11) : 16907 - 16931
  • [6] Novel Multi-Server Authentication Protocol using Secret Sharing
    Nimmy, K.
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON DATA MINING AND ADVANCED COMPUTING (SAPIENCE), 2016, : 214 - 219
  • [7] A multi-server architecture authentication protocol using smart card
    Yu, Jie
    Pei, Qingqi
    PROCEEDINGS OF THE 2012 EIGHTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS 2012), 2012, : 511 - 515
  • [8] A secure and improved multi server authentication protocol using fuzzy commitment
    Hafeez Ur Rehman
    Anwar Ghani
    Shehzad Ashraf Chaudhry
    Mohammed H. Alsharif
    Narjes Nabipour
    Multimedia Tools and Applications, 2021, 80 : 16907 - 16931
  • [9] A robust ElGamal-based password-authentication protocol using smart card for client-server communication
    Maitra, Tanmoy
    Obaidat, Mohammad S.
    Amin, Ruhul
    Islam, S. K. Hafizul
    Chaudhry, Shehzad Ashraf
    Giri, Debasis
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (11)
  • [10] Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment
    Barman, Subhas
    Das, Ashok Kumar
    Samanta, Debasis
    Chattopadhyay, Samiran
    Rodrigues, Joel J. P. C.
    Park, Youngho
    IEEE ACCESS, 2018, 6 : 38578 - 38594