Title:
Vulnerabilities in SNMPv3

Thumbnail Image
Author(s)
Lawrence, Nigel Rhea
Authors
Advisor(s)
Traynor, Patrick
Advisor(s)
Editor(s)
Associated Organization(s)
Supplementary to
Abstract
Network monitoring is a necessity for both reducing downtime and ensuring rapid response in the case of software or hardware failure. Unfortunately, one of the most widely used protocols for monitoring networks, the Simple Network Management Protocol (SNMPv3), does not offer an acceptable level of confidentiality or integrity for these services. In this paper, we demonstrate two attacks against the most current and secure version of the protocol with authentication and encryption enabled. In particular, we demonstrate that under reasonable conditions, we can read encrypted requests and forge messages between the network monitor and the hosts it observes. Such attacks are made possible by an insecure discovery mechanism, which allows an adversary capable of compromising a single network host to set the keys used by the security functions. Our attacks show that SNMPv3 places too much trust on the underlying network, and that this misplaced trust introduces vulnerabilities that can be exploited.
Sponsor
Date Issued
2012-07-10
Extent
Resource Type
Text
Resource Subtype
Thesis
Rights Statement
Rights URI