请输入您要查询的百科知识:

 

词条 Relay attack
释义

  1. Example attack

  2. External links

{{Context|date=October 2009}}

A relay attack in computer security is a type of hacking technique related to man-in-the-middle and replay attacks. In a classic man-in-the-middle attack, an attacker intercepts and manipulates communications between two parties initiated by one of the parties. In a classic relay attack, communication with both parties is initiated by the attacker who then merely relays messages between the two parties without manipulating them or even necessarily reading them.

Example attack

Peggy works in a high security building that she accesses using a smart card in her purse. When she approaches the door of the building, the building detects the presence of a smart card and initiates an exchange of messages that constitute a zero-knowledge password proof that the card is Peggy's. The building then allows Peggy to enter. Mallory wants to break into the building. Mallory approaches the building with a device that simulates a smart card, and the building responds by initiating the exchange of messages. Mallory forwards the message to her accomplice Evelyn who is tailing Peggy as she runs errands in another part of town. Evelyn relays the message to Peggy's smart card, listens for the answer, and forwards the answer to Mallory, who relays it to the building. Continuing in this way, Mallory and Evelyn relay messages between the building and Peggy's smart card until the building is satisfied that it is communicating with Peggy's smart card. The building opens and Mallory enters.

External links

  • Academic Survey on Relay Attacks
  • Detailed Practical Example of Relay Attack on RFID system
  • [https://www.youtube.com/watch?v=VxeqiBG18xA Relay Attack Demonstration] (and related [https://github.com/nfcgate/nfcgate Software] and Paper)
  • Practical Relay Attack on Contactless Transactions by Using NFC Mobile Phones

2 : Hacking (computer security)|Computer security exploits

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/13 1:13:40