DOAJ Open Access 2024

Integrity Check Value, Are You a Spy? Information Leakage Attack on Archive Formats

Donghyun Kim Jongwook Jeong Soo-Hyun Lee So Hyun Kang Youn Kyu Lee

Abstrak

Existing archive formats provide encryption to protect data, but vulnerabilities in these formats can lead to data leakage. This study proposes a novel attack to leak original data from encrypted archive files by exploiting the integrity check value and unencrypted metadata. The proposed attack obtains the size of the original data and the integrity check value by parsing the encrypted file, and identifies the original data by leveraging password-cracking techniques. Experiments with seven archive formats and seven utilities demonstrate the effectiveness of our proposed attack, successfully leaking data from 11 out of 20 encrypted files. This research uncovers vulnerabilities in existing archive formats and contributes to the design of more secure archiving systems.

Penulis (5)

D

Donghyun Kim

J

Jongwook Jeong

S

Soo-Hyun Lee

S

So Hyun Kang

Y

Youn Kyu Lee

Format Sitasi

Kim, D., Jeong, J., Lee, S., Kang, S.H., Lee, Y.K. (2024). Integrity Check Value, Are You a Spy? Information Leakage Attack on Archive Formats. https://doi.org/10.1109/ACCESS.2024.3416690

Akses Cepat

PDF tidak tersedia langsung

Cek di sumber asli →
Lihat di Sumber doi.org/10.1109/ACCESS.2024.3416690
Informasi Jurnal
Tahun Terbit
2024
Sumber Database
DOAJ
DOI
10.1109/ACCESS.2024.3416690
Akses
Open Access ✓