AIRlok Invulnerable to Flaw that Could Crash the Internet
Miami, FL May 10, 2004 -- In response to recent announcements by the US and UK governments that a flaw affecting the Internets Transmission Control Protocol (TCP) could be exploited by hackers to bring down the Internet, Lok Technology announces that its AIRlok(TM) Network Infrastructure Appliance is invulnerable to these threats. The AIRlok Appliance may be the solution for vulnerable networks that use popular routers and firewalls provided a number of networking equipment manufacturers including Cisco and Juniper Networks. The AIRlok, used to manage and secure wireless networks, including the increasingly popular Wi-Fi, has numerous built-in software and hardware-based defenses against TCP connection spoofing and hijacking.
On Tuesday, April 20, The US Department of Homeland Securitys U.S. Computer Emergency Response Team (US-CERT) along with England's National Infrastructure Security Coordination Centre (NISCC) announced that a computer researcher from Milwaukee had identified a method whereby hackers can trick personal computers and routers into shutting down by resetting the machines remotely in just matter of minutes. Previously researchers believed that such a feat would require calculations spanning 4 to 142 years. Cisco has issued advisories to warn that its IOS operating system used in many models of its popular router is vulnerable to this flaw. Juniper Networks has posted a security alert on its web site indicating that certain series of its routers as well as all NetScreen firewalls running ScreenOS earlier than release 5.0R6 are affected by this development.
Large-scale disruptions of the Internet could leave enterprises and government organizations without critical communication tools such as email and instant messaging.
Lok Technology launched its Internet infrastructure appliance, AIRlok, last autumn to meet the increasing demand from enterprises, telecom carriers and Internet Service Providers (ISPs) for more secure wireless (including Wi-Fi) and wireline networking. The AIRlok employs both software and hardware configurations that make the AIRlok one of the few network management solutions that can foil efforts by hackers to disrupt enterprise communications, e-commerce and government services that increasingly rely on the Internet. At the core the AIRloks defenses is the use of the OpenBSD operating system.
OpenBSD (www.openbsd.org) is an open source project that emphasizes correctness, security, standardization, and portability. OpenBSDs focused security approach makes it the most secure operating system in the world. Simon Lok, Chief Scientist and Founder of Lok Technology states, We run OpenBSD for this very reason. The developers of OpenBSD have a methodology that results in proactively secure systems. The recently announced TCP vulnerability is only the latest in a series of examples of how the proactive approach of the OpenBSD team thwarts attack and exploitation methods years in advance of their coming.
A TCP sequence number exploit requires that the attacker correctly guess the initial sequence number (ISN) and/or subsequent sequence numbers. In technical terms, many vendors have chosen to employ predictable ISN generators despite the fact that numerous Requests for Comment (RFCs) regarding TCP clearly state the importance of randomized values for the ISN. These shortcuts change the nature of TCP sequence number exploits against their products from the range of the possible to the practical. In OpenBSD, the ISN is chosen using a cryptographically strong pseudo random number generator (PRNG) seeded from the kernel entropy pool, thereby thwarting predictability.
In addition, successful execution of a TCP sequence number attack requires that the attacker correctly provide the TCP 4-tuple (source address, destination address, source port, destination port). The UK NISCC release states As the source port varies, additional work is generally called for on the part of the attacker. Once again, many vendors have chosen to use very simple source port number generators. In OpenBSD, the source port is also chosen using a cryptographically strong PRNG.
Lok Technology takes an additional step by shipping a FIPS-140-1 certified hardware random number generator (HW-RNG) with every appliance. A driver developed by the OpenBSD team (in conjunction with Lok Technology support) feeds the kernel entropy pool with true entropy. This makes attacks against OpenBSD subsystems that depend on entropy (e.g. TCP sequence number exploits) even more impractical.
Both the NISCC and US-CERT advisories suggest that employing ingress and egress filtering as an important step towards mitigating the damage that can be caused by the TCP exploit. In conjunction with its 12 dynamic functions that manage and secure networks that support a few dozen to several thousand users, the AIRlok implements an intrusion protection system (IPS) and stateful firewall. By default, an AIRlok provides address spoofing prevention as well as automatic blackholing of devices that attempt to perform flooding attacks.
The AIRlok is currently distributed in the US and UK for use by telecommunications carriers, Internet Service Providers (ISPs), Wireless ISPs, and enterprises.
Company:
LokTek
Related press releases
-
AIRlok Invulnerable to Flaw that Could Crash the Internet
[2004-05-10 00:00:00]
In response to recent announcements by the US and UK governments that a flaw affecting the Internets Transmission Control Protocol (TCP) could be exploited by hackers to bring down the Internet, Lo... -
Comodo SSL Certificates Not Affected By MD5 Flaw
[2009-01-08 05:28:16]
Jersey City, NJ, January 8, 2009 - Comodo CA Limited, the second-largest issuer of high-assurance digital certificates, today announced that none of its certificates is created using the MD5 hash func... -
Comodo Offers Free Replacement Certificate to any Individuals Affected by Debian...
[2008-05-21 11:06:23]
Comodo issues security advisory on Debian vulnerability flaw, confirming that while Comodo Certificates are unaffected, some certificates created using Debian Distribution are vulnerable which is why ... -
IE7Pro : An ultimate Add-On for IE7
[2007-04-27 03:17:59]
I've been using IE7Pro for a few weeks I really really like it. Some would say it brings some of the Firefox goodness to IE7. IE7Pro's Features Enhance Internet Explorer's Tabbed Browsing Capabil... -
Crazy Crash Racing presents a car racing game!
[2006-02-06 00:00:00]
FunGamesGalaxy.com Crazy Crash Racing presents a car racing game! February 6, 2006 For Immediate Release http://www.fungamesgalaxy.com The game Crazy Crash Racing is right what you need if you are so ... -
Airbag black box crash data recovery information for GM and Saturn vehicles.
[2004-09-04 00:00:00]
Vetronix crash data retrieval tool (CDR) collects GM vehicle crash data via the airbag system SDM. Nashville, Tennessee, June 15, 2004 -- For many years, airplane crash investigators have had the b... -
Comodo's TrustConnect Eliminates the Security Flaw that Firesheep Raises Red Fla...
[2010-11-10 03:59:04]
JERSEY CITY, NJ, November 10, 2010 - Comodo Security Solutions, Inc., a leading Internet security vendor, announced today that a WiFi hotspot security flaw recently uncovered and publicized by Fireshe... -
DVDFab Newly Releases Version 8.0.8.5 with Many Improvements
[2011-03-24 05:36:58]
DVDFab 8.0.8.5 was out on March 19, 2011. It has many improvements and fixes some problems in Blu-ray 3D Ripper, Blu-ray to DVD Converter and Video Converter. It specially fixed a crash problem at sta... -
AdvertMarket Poses a Threat to the Future of Online Marketing
[2004-09-11 00:00:00]
The future of online marketing has been in the midst of change ever since the crash a few years ago. AdvertMarket is threatening the way advertising is currently being sold by leading the internet int... -
AQUATRA Releases Backup Expert 2.2 - Backup Important Data Before a Computer Cra...
[2009-09-17 08:30:22]
Computer crashes and hard disk failures are an unfortunate matter of "when", and not "if". Prepare yourself for upcoming system crash, minimize your losses and save time on restoring your PC back to f...
English
German
French
Spanish
Russian
Romanian



