CMP | United Business Media

EE Times
Home
About
Feedback
EETimes Network
EETimes AsiaEETimes ChinaEETimes FranceEETimes GermanyEETimes KoreaEETimes TaiwanEETimes USSubscribeNewsletterContactMedia Kit
 


 
Search
departments
Technology
Business
Distribution
EE Times' Resource for Design Tools & Methodologies
EE Times' Work & Career Community
EE Times' Resource for Comms Designers
EE Times' Analog & Mixed-signal Resource
EE Times' Resource for Embedded Designers





Network Resources
eLibrary
   

 Online Editions
 EE TIMES
 EE TIMES ASIA
 EE TIMES CHINA
 EE TIMES FRANCE
 EE TIMES GERMANY
 EE TIMES KOREA
 EE TIMES TAIWAN
 EE TIMES UK

 Web Sites
   Web Sites
 • Career Center
 • CommsDesign
 • Microwave
    Engineering
 • EEdesign
 • Deepchip.com
 • Design & Reuse
 • Embedded.com
 • Embedded Edge
   Magazine
 • Elektronik i Norden
 • Planet Analog
 • Silicon Strategies
 • Wireless Solutions
   Magazine



 • eeProductCenter
 • Electronics Supply &
    Manufacturing
 • Conferences
    and Events
 • Custom Magazines
 • EBN China
 • Electronics Express
 • NetSeminar Services
 • QuestLink


 
Technology

TCP vulnerability could lead to bigger gateway protocol problems

By Loring Wirbel
EE Times
22 April 2004 (4:49 p.m. GMT)

 
Recent Articles
Technology
  • Test consortium expands
  • Amphion releases H.264/AVC hardware video decoder core
  • Consultant begins work on EDA 'encyclopedia'
  • Theory promises brighter plastic LEDs
  • UK designers use tool for automated library development
  • picoChip accelerates WiMAX development
  • Widex uses laser technology to improve hearing aid manufacture

    Archives
    DENVER — A vulnerability in the Transmission Control Protocol discovered by researchers last year could cause greater than anticipated problems with inter-domain routing using the Border Gateway Protocol, the Department of Homeland Security warned this week.

    In a Technical Cyber Security Alert published at its new Web site, the agency warned that the TCP vulnerability allows remote attackers to terminate TCP sessions, which could lead to widespread denial-of-service problems.

    The original TCP study by Paul Watson of Milwaukee prompted efforts by Cisco Systems Inc. to implement patches in the Internetwork Operating System used throughout its routers. Additional research by Cisco and the Internet Systems Consortium identified a problem with BGP application re-starts caused by TCP vulnerabilities.

    Several Internet consortia have suggested the regular use of MD5 hashing signatures on TCP headers, or BGP tunneling over IPsec, to provide greater security in session creation.

    The agency's solutions could shift the current interest in using high-layer security protocols like secure sockets layer as virtual private networks. The security alert noted that since SSL and SSH1/SSH2 do not prevent a TCP connection re-start, it is better to use Layer 3 cryptographic solutions such as IPsec to create secure TCP sessions.

    The department's Computer Emergency Readiness Team also issued a warning Tuesday (April 20) for Cisco's earlier use of hardwired support for Simple Network Management Protocol, though the implications of the SNMP vulnerability were less critical than the BGP/TCP problem. Cisco said it has already identified several solutions.


     

     

     


     
     

    New Samtec Board-to-Board & I/O Interface Catalog
    Samtec F-204 Full Line Catalog has been expanded to include new high speed and high density interfaces, micro board-to-board and I/O interfaces, cable/wire/flex systems and micro-rugged power and circular connectors.

    Free National Instruments Visual Basic Tutorial
    Free technical tutorial to help you develop a simple data acquisition application by leveraging tools in Measurement Studio for the Visual Basic environment.

    FREE Windows-based software package
    Designed for the IFR3410 Series digital RF generator, IQ Creator is a FREE software package enabling users to create waveform files that emulate digital RF transmission formats. Download now.

    Signal Integrity for High Frequency Board Design
    "Learn for GHz designs: relevant interconnect standards, BER prediction and analysis, signal integrity performance factors, via and power plane design, NRZ and 4PAM signaling differences, 8B10B encoding benefits, eye diagram analysis. Free webin...

    Prototype Circuit Boards from PCBexpress
    Leading Internet supplier of prototype circuit boards. Successfully selling pcbs online since 1997. Easy order process for quick turn pcbs (24-hrs) 2-6 layers up to 20 pieces. No tooling charges for our quality prototype boards. Try us out today.

    Buy a link NOW:



    Electronics Times and EETimes UK material Copyright © 2004 CMP Europe Ltd.
    All other material Copyright © 2004 CMP Media LLC
    Terms and Conditions and privacy.