Prospective Ideas

Cryptographic Back-doors

Schneier states in [6] about cryptographic vulnerabilities:

A great many systems “void the warranty” of their cryptography by using it improperly: They fail to check the size of values, reuse random parameters that should never be reusedand so on. Encryption algorithms don’t necessarily provide data integrity. Key exchange protocols don’t necessarily ensure that both parties receive the same key. […] Random-number generators are another place where cryptographic systems often break.

For the purpose of the enquiry, more complex applications like GPG have been considered. It is an implementation of the OpenPGP standard, as defined by RFC4880, which serves as a key manager, encryption and signing tool. The outline of an approach for inserting back-doors has been delimited and the relevant scenario would make this challenge worth solving for bringing into attention the power of such back-doors.

A potential way is to introduce bugs in GnuPG 2.1.21 and to actually test the behaviour in the experimental remote shell presented previously(See Figure “GPG Authentication Remote Shell”) By finding gpg explored code paths (using gcov) for the common commands below, one will be able to identify the fragments of code to modify by including one of the compiler bug triggers.

Commands for generating keys and checking current keys:

  1. gpg–full-gen-key (Creates a key pair. I assume only RSA is used.)

  2. gpg–list-keys

  3. gpg–list-secret-keys

Command to export the public key:

  1. gpg–output destination_public.key –armor –export user_id

Command to import the key on the server:

  1. gpg–import public.key

Encrypt using public key:

  1. gpg–recipient user_id –encrypt plain_text_msg_file (The result is an encrypted_message_file)

Decrypt using private key:

  1. gpg–output plain_text_msg_file –decrypt encrypted_message_file (The result is a plain_text_msg_file)

Developing an automated detection tool

Understanding the patterns and approaching the problem using a DSL can be effective in searching large code-bases for patterns that trigger compiler bugs. The difficulty arises from the need of a large collection of malicious patterns. Compiler passes can be run in batches once these are gathered. Fuzzing is an effective way of generating a large class of programs containing the malicious patterns.

Using Varan to detect back-doors being triggered

Previous work has proven that multi-version execution is an effective solution for defeating compiler-backdoors by signaling inconsistent system call traces (https://blog.regehr.org/archives/1282).