Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

New research on Bluetooth vulnerability

Дата публикации: 19-08-2019 11:00:00



Основное содержимое страницы с новостью.

Posted: 19th August 2019

Professor Kasper Rasmussen is part of an international team of researchers that authored a paper to expose a vulnerability in the Bluetooth wireless communication protocol commonly used to connect personal devices. In the paper, the team exposed a Bluetooth vulnerability that enables an attacker to listen in on, or change the content of, information shared between Bluetooth devices, even if the devices have previously been successfully paired.

In the paper, titled “The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDR”, the researchers presents an attack on the key negotiation of the Bluetooth protocol (KNOB). The attack exploits a mechanism present in all on standard-compliant Bluetooth devices, which enables the negotiation of a cryptographic key with reduced entropy.  The Bluetooth protocol is present in everyday items such as mobile phones or wireless headphones, and the attack therefore impacts all such devices. The attack targets the firmware of the Bluetooth chip which means that a firmware upgrade is required to fix the problem.

The attack and proof of concept code has demonstrated the vulnerability and has been taken very seriously by industry. In November 2018, the details of the attack were shared with the Bluetooth Special Interest Group—the standards organization that oversees the development of Bluetooth standards—and with the CERT Coordination Center and the International Consortium for Advancement of Cybersecurity on the Internet (ICASI). After the attack was disclosed to industry in late 2018, some vendors may have since implemented workarounds for the vulnerability on their devices.

Read more details and full paper here: https://knobattack.com/  

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1New research to be unveiled at Black Hat conference this week01025-07-2017
2New research in antibiotic resistance01024-01-2019
3REF2021 IMPACT CASE STUDY: Resolution of Multiple Critical Design Flaws in Bluetooth Standard09.4211-07-2024
4New U-Boot flaws could enable stealthy firmware attacks-2710-07-2026
5Overcoming mobile biometric challenges: Mastercard and University of Oxford collaborate on new research initiative01013-06-2017
6Research seeks to codify negative impact of cyber attack01024-10-2018
7Атакована недоисправленная уязвимость в Windows-2609-07-2026
8Latest Canvas Attack Shows Schools Still Struggle With Cybersecurity01012-05-2026
9New research paper puts the case for an 'ethical black box' for robots08.5220-07-2017
10Bluetooth в зоне досягаемости — и ваше авто можно угнать. Специалисты раскрыли уязвимость сигнализации KARR014.5522-07-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10. Источник: www.cs.ox.ac.uk.