{"title":"Previously overlooked bias signatures for RC4","authors":"M. Hammood, K. Yoshigoe","doi":"10.1109/ISDFS.2016.7473526","DOIUrl":null,"url":null,"abstract":"Recent findings suggest that known short-term and long-term biases for RC4 can be practically exploited to capture extended part of the Internet traffic relying on Transportation Layer Security (TLS) with RC4 cipher. While RC4 is no longer a dominant cipher used in the Internet, research community continues to exploure its characteristics and even propose its derivatives. To the best of our knowledge, no works have correctly verified the set of well-known Fluhrer-McGrew biases. We experimentally approached to validate the correctness of the biases during which we uncovered two additional biases. Furthermore, our experiment has successfully produced and generalized a set of non-consecutive byte biases from RC4 keystream. Finally, we have captured bias signatures for several well-known RC4 variants.","PeriodicalId":136977,"journal":{"name":"2016 4th International Symposium on Digital Forensic and Security (ISDFS)","volume":"342 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-04-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 4th International Symposium on Digital Forensic and Security (ISDFS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISDFS.2016.7473526","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Recent findings suggest that known short-term and long-term biases for RC4 can be practically exploited to capture extended part of the Internet traffic relying on Transportation Layer Security (TLS) with RC4 cipher. While RC4 is no longer a dominant cipher used in the Internet, research community continues to exploure its characteristics and even propose its derivatives. To the best of our knowledge, no works have correctly verified the set of well-known Fluhrer-McGrew biases. We experimentally approached to validate the correctness of the biases during which we uncovered two additional biases. Furthermore, our experiment has successfully produced and generalized a set of non-consecutive byte biases from RC4 keystream. Finally, we have captured bias signatures for several well-known RC4 variants.