[ °ø Áö ] SSL 3.0 ÇÁ·ÎÅäÄÝ Ãë¾àÁ¡ ÁÖÀÇ ±Ç°í 2014-10-21

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

SSL 3.0 ÇÁ·ÎÅäÄÝ Ãë¾àÁ¡ ÁÖÀÇ ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------


°³¿ä
•SSL 3.0ÀÇ CBC ¸ðµå¸¦ »ç¿ëÇÒ °æ¿ì Áß°£ÀÚ °ø°Ý(MITM)À» ÅëÇØ ¾ÏȣȭµÈ µ¥ÀÌÅ͸¦ º¹È£È­ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2014-3566)ÀÌ ¹ß°ßµÊ [1,2]
•SSL 3.0Àº 1996³âµµ¿¡ °ø°³µÈ ¹öÀüÀ¸·Î ÀϺο¡¼­ ÇÏÀ§ ȣȯ¼ºÀ» À§ÇØ Á¦°øÇÏ°í ÀÖÀ¸³ª º¸¾ÈÀÌ Ãë¾àÇÏ¿© »ç¿ëÇÏÁö ¾Ê´Â °ÍÀ» ±Ç°í [1,2]

ÇØ´ç ½Ã½ºÅÛ
•¿µÇâ ¹Þ´Â Á¦Ç° ¹× ¹öÀü
◦SSL 3.0 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â ¾îÇø®ÄÉÀÌ¼Ç ¹× ½Ã½ºÅÛ

ÇØ°á ¹æ¾È
•ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¹öÀü »ç¿ëÀÚ
◦SSL 3.0À» »ç¿ëÇÏ´Â ¾îÇø®ÄÉÀÌ¼Ç ¹× ½Ã½ºÅÛÀÇ ¼³Á¤¿¡¼­ SSL 3.0 Áö¿ø ºñÈ°¼ºÈ­
◦SSL 3.0À» Áö¿øÇؾßÇϴ ȯ°æÀÇ °æ¿ì TLS_FALLBACK_SCSV ÇÁ·ÎÅäÄÝ È®Àå±â´ÉÀ» »ç¿ëÇÏ¿© °ø°Ý ¿¹¹æ(POODLE °ø°Ý)

¿ë¾î ¼³¸í
•SSL(Secure Socket Layer) : ³×Æ®¿öÅ© µ¥ÀÌÅ͸¦ ¾ÏȣȭÇϱâ À§ÇØ »ç¿ëÇÏ´Â ÇÁ·ÎÅäÄݵéÀÇ ÁýÇÕ
•CBC(Cipher Block Chaining) : ºí·Ï ¾Ïȣȭ ¾Ë°í¸®ÁòÀ» »ç¿ëÇÏ¿© °¡º¯ ±æÀÌÀÇ µ¥ÀÌÅ͸¦ ¾ÏȣȭÇÏ´Â ¹æ½Ä
•POODLE(Padding Oracle On Downgraded Legacy Encryption) : SSL 3.0ÀÇ CBC ¸ðµå¸¦ °ø°ÝÇÏ´Â ¹æ¹ý

±âŸ ¹®ÀÇ»çÇ×
•Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118


[Âü°í»çÀÌÆ®]
[1] https://www.openssl.org/~bodo/ssl-poodle.pdft
[2] https://www.us-cert.gov/ncas/alerts/TA14-290A/


°¨»çÇÕ´Ï´Ù.

---------------------------------------------------------------------------

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆà ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]