Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

WireGuard: Next Generation Secure Kernel Network Tunnel Cutting edge crypto, shrewd kernel design, …

Автор: FOSDEM

Загружено: 2018-03-06

Просмотров: 4554

Описание:

WireGuard: Next Generation Secure Kernel Network Tunnel Cutting edge crypto, shrewd kernel design, and networking meet in a surprisingly simple combination
by Jason A. Donenfeld

At: FOSDEM 2017

WireGuard is a next generation VPN protocol, which lives in the Linux kernel,and uses state of the art cryptography. One of the most exciting recentcrypto-networking developments, WireGuard aims to drastically simplify securetunneling. The current state of VPN protocols is not pretty, with popularoptions, such as IPsec and OpenVPN, being overwhelmingly complex, with largeattack surfaces, using mostly cryptographic designs from the 90s. WireGuardpresents a new abuse-resistant and high-performance alternative based onmodern cryptography, with a focus on implementation and usability simplicity.It uses a 1-RTT handshake, based on NoiseIK, to provide perfect forwardsecrecy, identity hiding, and resistance to key-compromise impersonationattacks, among other important security properties, as well as highperformance transport using ChaCha20Poly1305. A novel IP-binding cookie MACmechanism is used to prevent against several forms of common denial-of-serviceattacks, both against the client and server, improving greatly on those ofDTLS and IKEv2. Key distribution is handled out-of-band with extremely shortCurve25519 points, which can be passed around in the likes of OpenSSH.Discarding the academic layering perfection of IPsec, WireGuard introduces theidea of a "cryptokey routing table", alongside an extremely simple and fullydefined timer-state mechanism, to allow for easy and minimal configuration;WireGuard is actually securely deployable in practical settings. In order torival the performance of IPsec, WireGuard is implemented inside the Linuxkernel, but unlike IPsec, it is implemented in less than 4,000 lines of code,making the implementation manageably auditable. These features converge tocreate an open source VPN utility that is exceedingly simple, yet thoroughlymodern and secure.

The presentation will be divided up into several parts. First, there will bean overview of the problems with IPsec, OpenVPN, and other popular VPNs,outlining attacks and weaknesses. Next, the WireGuard idea of the "cryptokeyrouting table" will be introduced, and we’ll walk through several propertiesderived from it. This will transition into a discussion of the timer statemechanism, and how secure protocols are necessarily stateful, but it’spossible to make them appear stateless to the user by exhaustively definingall possible state transitions. Then we’ll get into the hardcore meat of thepresentation: the cryptography and various crypto innovations behindWireGuard. We will discuss the triple Diffie-Hellman, the role of combiningstatic and ephemeral keys, the performance and DoS-potential of Curve25519point multiplication, using a PRF chaining for rotating keys, identity hidingand remaining silent on a network, and clever usage of authenticatedencryption with additional data. We will examine the various attack models,and enumerate the cryptographic mitigations employed by WireGuard. The sumwill be a comprehensive overview of modern day crypto tricks, attacks, anduseful constructions, and how these insights have been funneled intoWireGuard. Finally, we’ll examine the Linux kernel implementation ofWireGuard, seeing how it’s possible to avoid allocations in response tounauthenticated packets as a defense coding technique. During thepresentation, a live WireGuard endpoint will be provided to audience memberswho wish to send packets, whether encrypted, legitimate, malformed, dubious,or otherwise curious.

Threaded throughout will be an enumeration of attacks on existing protocolsand cryptographic tricks for their mitigation.

My background is in security -- kernels, hardware, reversing, crypto, largenetworks, etc -- and as such I've broken a lot of systems with some noveltricks and protocol insights. WireGuard is motivated by a sort of cornucopiaof clever attacks (crypto and otherwise) against other networks. I made itbecause I wanted something I could actually confidently run on my owninfrastructure, and none of the other tools were nearly up to the task. So,this talk is going to go into depth about real attacks on various protocols,in addition to unveiling some techniques to avoid entire classes of attacks.

Finally, since WireGuard is initially implemented for the Linux kernel, therehave been some very interesting considerations to account for with kernelprogramming. Cross platform implementations are also in the works, written inGo and Rust.


Room: Janson
Scheduled start: 2017-02-05 13:00:00

WireGuard: Next Generation Secure Kernel Network Tunnel Cutting edge crypto, shrewd kernel design, …

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Closing FOSDEM 2017

Closing FOSDEM 2017

WireGuard: Next Generation Secure Network Tunnel

WireGuard: Next Generation Secure Network Tunnel

LPC2018 - WireGuard: Next-Generation Secure Kernel Network Tunnel

LPC2018 - WireGuard: Next-Generation Secure Kernel Network Tunnel

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Wireguard, Jason A. Donenfeld, SSTIC 2018

Wireguard, Jason A. Donenfeld, SSTIC 2018

Python Data Structures implementation list, dict: how does CPython actually implement them?

Python Data Structures implementation list, dict: how does CPython actually implement them?

Life of a Packet [I] - Michael Rubin, Google

Life of a Packet [I] - Michael Rubin, Google

LinuxKit Security SIG: WireGuard Deep Dive

LinuxKit Security SIG: WireGuard Deep Dive

Understanding The Complexity of Copyleft Defense After 25 Years of GPL Enforcement, Is Copyleft Suc…

Understanding The Complexity of Copyleft Defense After 25 Years of GPL Enforcement, Is Copyleft Suc…

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

MINIX 3: a Modular, Self-Healing POSIX-compatible Operating System

MINIX 3: a Modular, Self-Healing POSIX-compatible Operating System

WireGuard VPN — лучше платных сервисов и проще OpenVPN. Полная настройка WireGuard!

WireGuard VPN — лучше платных сервисов и проще OpenVPN. Полная настройка WireGuard!

Акунин ошарашил прогнозом! Финал войны уже решён — Кремль скрывает правду

Акунин ошарашил прогнозом! Финал войны уже решён — Кремль скрывает правду

The billion dollar race for the perfect display

The billion dollar race for the perfect display

Linux Networking - eBPF, XDP, DPDK, VPP - What does all that mean? (by Andree Toonk)

Linux Networking - eBPF, XDP, DPDK, VPP - What does all that mean? (by Andree Toonk)

Как финский гик ВЫНЕС Майкрософт и стал богом айти // Линус Торвальдс

Как финский гик ВЫНЕС Майкрософт и стал богом айти // Линус Торвальдс

Microsoft становится ржавеющей: обзор успехов и проблем — Марк Руссинович

Microsoft становится ржавеющей: обзор успехов и проблем — Марк Руссинович

Интернет в небе: Сергей

Интернет в небе: Сергей "Флеш" о том, как «Шахеды» и «Герберы» научились работать в одной связке

Как Ubuntu Предала Linux - Вся Правда о Взлёте и Падении Canonical

Как Ubuntu Предала Linux - Вся Правда о Взлёте и Падении Canonical

"We Really Don't Know How to Compute!" - Gerald Sussman (2011)

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]