3.7 Cryptanalytic Attacks
3.7 Cryptanalytic Attacks
Cryptanalytic attacks attempt to defeat cryptographic protection or exploit weaknesses in the way cryptographic and authentication systems are designed, implemented or used.
For CISSP, it is important to distinguish between attacks against the mathematics of cryptography and attacks against implementations, credentials, protocols or surrounding systems.
Attack the Cipher
Analyse ciphertext, known information or the key space.
CRYPTOANALYSISAttack the Implementation
Exploit timing, physical leakage, faults or programming weaknesses.
IMPLEMENTATIONAttack the Trust
Abuse credentials, tickets, protocols or communication relationships.
AUTHENTICATIONThe Big Idea
A cryptographic algorithm can be mathematically strong while the overall system remains vulnerable.
An attacker may try several completely different approaches.
Cryptanalytic Attack Memory Aid
Attackers do not have to break the cipher if there is an easier way.
Attacks You Need to Recognise
| Attack | Main Idea |
|---|---|
| Brute Force | Try possible keys or credentials until one works. |
| Ciphertext-Only | Analyse encrypted information without knowing the plaintext. |
| Known-Plaintext | Use known plaintext/ciphertext relationships to learn about the cryptosystem. |
| Frequency Analysis | Use statistical patterns in encrypted information. |
| Chosen-Ciphertext | Observe how selected ciphertext is processed or decrypted. |
| Implementation Attack | Exploit how cryptography was implemented rather than its mathematics. |
| Side-Channel | Learn secrets from indirect physical or computational leakage. |
| Fault Injection | Induce errors and analyse resulting behaviour. |
| Timing Attack | Learn secrets from differences in execution time. |
| Man-in-the-Middle | Intercept and potentially alter communications between parties. |
| Pass-the-Hash | Reuse captured password-hash-derived authentication material. |
| Kerberos Exploitation | Abuse tickets, keys, accounts or Kerberos trust relationships. |
| Ransomware | Use malware, often including encryption, to deny access and extort the victim. |
๐ช Brute-Force Attack Try possibilities until the correct value is found
A brute-force attack attempts possible values until the correct key, password or other secret is discovered.
What Makes Brute Force Difficult?
More possible keys require more attempts.
Unpredictable secrets reduce useful shortcuts.
Appropriate password hashing makes each password guess more expensive.
Online systems can restrict repeated authentication attempts.
A well-generated cryptographic key with a sufficiently large key space may make exhaustive search computationally impractical.
A human-selected password may have far less effective entropy, even if the underlying encryption algorithm is strong.
The algorithm may be working exactly as designed.
The attacker is simply testing possibilities.
Brute Force
๐ Ciphertext-Only Attack The attacker initially has only encrypted information
In a ciphertext-only attack, the attacker has one or more ciphertexts and attempts to derive useful information about the plaintext or cryptographic key.
The attacker has less information than in known-plaintext or chosen input attacks.
An attacker intercepts many encrypted messages but has no confirmed copy of the corresponding plaintext.
They analyse the ciphertext looking for exploitable patterns or weaknesses.
๐ Known-Plaintext Attack The attacker knows some plaintext and its corresponding ciphertext
A known-plaintext attack assumes the attacker possesses examples of plaintext together with the corresponding ciphertext.
An attacker knows that a standard message header appears in a particular encrypted message.
They therefore possess part of the plaintext and its encrypted equivalent.
The attacker knows some message content.
The purpose of the attack may still be to recover key material or decrypt other information.
๐ฏ Chosen-Ciphertext Attack The attacker can select ciphertext and observe how it is processed
In a chosen-ciphertext attack, an attacker is able to submit selected ciphertext values to a system and obtain information about the resulting decryption or observable behaviour.
Error messages, response differences or other observable behaviour may reveal information about protected data.
๐ Chosen-Plaintext Attack A useful comparison with the current CISSP attack models
In a chosen-plaintext attack, an attacker can select plaintext values and obtain their corresponding ciphertext.
Although chosen plaintext is not separately listed in the current CISSP 3.7 bullet list, understanding it makes the attack models easier to compare.
What Does the Attacker Know?
| Attack | Attacker Has | Easy Memory Aid |
|---|---|---|
| Ciphertext-Only | Ciphertext only | SEE ciphertext |
| Known-Plaintext | Known plaintext + corresponding ciphertext | KNOW plaintext |
| Chosen-Plaintext | Ability to choose plaintext and observe ciphertext | CHOOSE plaintext |
| Chosen-Ciphertext | Ability to choose ciphertext and observe decryption behaviour | CHOOSE ciphertext |
Classical Attack Shortcut
๐ Frequency Analysis Use statistical patterns to infer information
Human languages and many forms of structured information contain statistical patterns.
Frequency analysis attempts to identify relationships between those patterns and encrypted symbols.
In English, some letters occur significantly more frequently than others.
If a simple substitution cipher maps the same plaintext letter to the same ciphertext symbol repeatedly, frequency patterns may remain visible.
Properly designed modern cryptographic algorithms aim to eliminate exploitable statistical relationships between plaintext and ciphertext.
Frequency Analysis
โ๏ธ Implementation Attacks Attack the implementation instead of the mathematical algorithm
A cryptographic algorithm can be mathematically secure while the software or hardware implementing it contains weaknesses.
Predictable keys or nonces can undermine otherwise strong cryptography.
Secret material may be stored or handled insecurely.
Different errors may reveal information about internal processing.
Sensitive keys may remain unnecessarily accessible in memory.
Physical or computational behaviour may leak information.
Secure primitives may be combined incorrectly.
An attacker does not break AES.
Instead, they discover that the application stores the AES key in an unprotected configuration file.
The cryptographic algorithm remains strong.
The implementation failed.
Implementation Attack
๐ก Side-Channel Attacks Observe something other than the intended cryptographic output
Side-channel attacks exploit information unintentionally leaked by the physical or computational behaviour of a cryptographic system.
Possible Side Channels
How long an operation takes.
Changes in electrical power while processing.
Signals emitted by operating hardware.
Sounds produced during computation.
Memory-access patterns observable through shared processor resources.
Other measurable characteristics associated with computation.
A cryptographic device uses slightly different amounts of power depending on operations involving secret key material.
Repeated measurements may reveal patterns correlated with the secret.
The attacker is learning about the secret from how the cryptographic operation physically behaves.
Mitigations
Side Channel
โฑ๏ธ Timing Attacks A specific form of side-channel analysis
Timing attacks examine how long cryptographic or security operations take.
If processing time depends on secret information, repeated observations may reveal useful patterns.
Timing is a specific observable characteristic of the implementation.
In cryptanalytic context, the key idea is that differences in processing duration reveal information about secret-dependent computation.
โก Fault Injection Cause the system to make mistakes and analyse the result
Fault-injection attacks deliberately cause abnormal behaviour while a cryptographic device or security mechanism is operating.
The attacker then studies the faulty result or changed behaviour.
Faults may be caused through environmental or physical manipulation of a device.
Mitigations
Fault Injection
๐ต๏ธ Man-in-the-Middle - MITM The attacker positions themselves between communicating parties
A Man-in-the-Middle attack places an attacker between communicating parties so communications can potentially be intercepted, relayed or modified.
Alice believes she is negotiating a secret directly with Bob.
Bob believes he is negotiating directly with Alice.
Without appropriate authentication, an attacker between them may establish separate relationships with both parties.
Secure communication also needs appropriate authentication and integrity protection.
Mitigations
MITM
#๏ธโฃ Pass-the-Hash Reuse authentication material instead of cracking the password
Pass-the-hash attacks abuse authentication systems in which possession of a password-derived hash can be sufficient to authenticate.
Password cracking attempts to determine the original password.
Pass-the-hash attempts to use the captured hash itself as authentication material.
Defensive Principles
Pass-the-Hash
๐๏ธ Kerberos Exploitation Attack tickets, secrets and trust relationships
Kerberos uses tickets and symmetric cryptography to provide network authentication.
Attackers do not necessarily need to break the Kerberos cryptographic algorithms.
Instead, they may attempt to steal or abuse:
Kerberos Refresher
Attack Concepts Worth Recognising
Reuse a stolen Kerberos ticket to access resources.
Obtain valid authentication tickets from a compromised system.
Poorly protected service secrets may create opportunities for credential attacks.
Compromise of critical Kerberos secrets can allow attackers to create fraudulent authentication tickets.
Excessive or inappropriate delegation can increase the effect of credential compromise.
Certain domain-level secrets have extremely high security value.
If an attacker obtains appropriate authentication material, they may be able to impersonate the legitimate identity without knowing the user's password.
Defensive Principles
Kerberos Attacks
๐ฆ Ransomware Cryptography used offensively to deny availability
Ransomware is malware designed to prevent organisations from accessing systems or information, commonly by encrypting files and demanding payment for restoration.
Double Extortion
Modern ransomware incidents may combine:
Prevent the victim from using systems or information.
Exfiltrate information and threaten disclosure.
Defensive Principles
A backup that is continuously accessible from compromised systems may itself be deleted, altered or encrypted.
Ransomware
What Is Actually Being Attacked?
| Target | Examples |
|---|---|
| Key Space | Brute force |
| Cipher Relationships | Ciphertext-only, known-plaintext, chosen-ciphertext, frequency analysis |
| Implementation | Implementation attacks, side channels |
| Physical Behaviour | Timing, power analysis, fault injection |
| Communication Trust | Man-in-the-Middle |
| Authentication Material | Pass-the-hash, Kerberos ticket exploitation |
| Availability | Ransomware encryption for impact |
Most Important Lesson
A Strong Cipher, Weak Architecture
A banking application encrypts sensitive information using a strong modern cryptographic algorithm.
The security team identifies several problems.
Encryption keys are stored in plaintext configuration files.
Implementation / key-management weakness
Cryptographic processing time varies based on secret data.
Timing side channel
The application does not properly authenticate its key-exchange peer.
MITM risk
Privileged authentication material is exposed on compromised endpoints.
Credential reuse risk
Backups remain permanently writable from production.
Ransomware recovery risk
Security depends on the entire architecture surrounding the cryptographic primitive.
๐ CISSP Scenarios Identify how the cryptographic system is being attacked
An attacker tries every possible cryptographic key until readable plaintext is produced.
Attack?
Brute force.
An attacker possesses only a collection of encrypted messages and attempts to recover their contents.
Attack model?
Ciphertext-only.
An attacker knows that a specific encrypted message contains a standard document header.
Attack model?
Known-plaintext.
An attacker can submit selected encrypted values to a system and observe differences in how they are processed.
Attack?
Chosen-ciphertext attack.
An attacker analyses repeated symbols in a classical substitution cipher and compares them with common letter patterns.
Attack?
Frequency analysis.
AES remains mathematically secure, but encryption keys are exposed through insecure application memory handling.
Attack category?
Implementation attack.
An attacker observes a cryptographic device's electrical power use while it performs private-key operations.
Attack?
Side-channel attack.
Differences in cryptographic processing duration correlate with secret values.
Attack?
Timing attack.
An attacker deliberately causes a cryptographic device to produce abnormal results and compares them with normal results.
Attack?
Fault injection.
Alice believes she has established a secure session with Bob, while an attacker has actually established separate sessions with both parties.
Attack?
Man-in-the-Middle.
An attacker obtains password-derived authentication material and authenticates without first recovering the user's plaintext password.
Attack?
Pass-the-hash.
A valid Kerberos ticket is stolen from a compromised system and later reused to access another service.
Attack concept?
Pass-the-ticket / Kerberos exploitation.
A highly sensitive Kerberos domain secret is compromised, threatening the trust placed in authentication tickets.
What is the larger concern?
Compromise of the Kerberos trust infrastructure can enable fraudulent authentication.
Malware encrypts production files and demands payment for restoration.
Attack?
Ransomware.
Ransomware operators steal customer records before encrypting production systems and threaten to publish the records.
What is this commonly called?
Double extortion.
A cryptographic system is resistant to mathematical attacks, but the CPU cache reveals secret-dependent memory-access patterns.
Attack category?
Side-channel / implementation attack.
The security team proposes replacing a compromised cipher even though investigation shows the attacker simply stole the encryption key from an unprotected file.
What should the team focus on first?
Correct the key-management and implementation weakness.
A key-agreement protocol is mathematically strong but does not authenticate either endpoint.
Which attack is particularly relevant?
Man-in-the-Middle.
Recognise the Clue Words
Try Every Key
Exhaustive search.
Brute ForceOnly Encrypted Data
No known message content.
Ciphertext-OnlyKnow Some Message Content
Plaintext + matching ciphertext.
Known-PlaintextChoose Encrypted Input
Observe decryption behaviour.
Chosen-CiphertextStatistical Patterns
Common symbols and language patterns.
Frequency AnalysisStrong Cipher, Bad Code
Implementation weakness.
Implementation AttackPower / EM / Cache
Indirect leakage.
Side ChannelProcessing Duration
Secret-dependent time differences.
Timing AttackInduce Errors
Analyse faulty cryptographic output.
Fault InjectionAttacker Between Parties
Intercept or modify communication.
MITMReuse Hash
No plaintext password required.
Pass-the-HashReuse Kerberos Ticket
Authentication ticket becomes the credential.
Pass-the-TicketEncrypt for Extortion
Availability impact.
Ransomwareโ ๏ธ Common CISSP Mistakes Understand what is actually being attacked
Brute force may simply test the complete search space.
Ciphertext-only means the attacker initially possesses only ciphertext.
Known-plaintext means some corresponding plaintext is already known.
Knowing some original content does not mean the secret key is known.
The attack gains information from how selected ciphertexts are processed.
Frequency analysis exploits statistical patterns.
Brute force searches possible secrets.
The attacker observes implementation behaviour such as timing, power or electromagnetic leakage.
Timing is one specific form of observable implementation leakage.
The attacker actively induces abnormal behaviour and analyses the result.
A communication can be encrypted while still vulnerable to an attacker impersonating one of the endpoints.
Pass-the-hash reuses authentication material directly.
Many Kerberos attacks abuse stolen tickets, secrets, privileges or configuration rather than breaking the underlying cryptography.
Encryption by ransomware primarily creates an availability problem, while data theft can additionally create a confidentiality breach.
Quick Reference
| If you see... | Think... |
|---|---|
| Try every possible key | Brute Force |
| Only encrypted messages available | Ciphertext-Only |
| Some plaintext and ciphertext both known | Known-Plaintext |
| Statistical letter or symbol patterns | Frequency Analysis |
| Choose ciphertext and observe processing | Chosen-Ciphertext |
| Strong algorithm but weak software | Implementation Attack |
| Power, EM, cache or acoustic information | Side Channel |
| Different execution times reveal information | Timing Attack |
| Deliberately induce incorrect cryptographic operation | Fault Injection |
| Attacker positioned between communicating parties | MITM |
| Reuse password hash rather than recover password | Pass-the-Hash |
| Reuse a Kerberos ticket | Pass-the-Ticket |
| Attack Kerberos keys, tickets or service identities | Kerberos Exploitation |
| Files encrypted and ransom demanded | Ransomware |
Cryptanalytic Attack Master Memory Aid
The Easiest Way to Think About 3.7
Math ยท Machine ยท Middle ยท Credential ยท Impact
Key Takeaways
Cryptanalysis attempts to defeat cryptographic protection or exploit weaknesses in cryptographic systems.
A secure algorithm does not guarantee a secure implementation.
Brute force tests possible keys or secrets rather than necessarily exploiting a weakness in the algorithm.
Ciphertext-only attacks begin with encrypted information and no confirmed corresponding plaintext.
Known-plaintext attacks use known plaintext/ciphertext relationships.
Chosen-ciphertext attacks allow the attacker to select ciphertext and learn from how the cryptographic system processes it.
Frequency analysis uses statistical patterns and is particularly associated with classical cryptographic systems.
Implementation attacks exploit weaknesses surrounding the algorithm rather than necessarily defeating its mathematics.
Side-channel attacks obtain information from characteristics such as execution time, power consumption, electromagnetic emissions, acoustic emissions or memory behaviour.
Timing attacks are a specific form of side-channel attack.
Fault-injection attacks deliberately create abnormal system behaviour and analyse the resulting output.
Man-in-the-Middle attacks place an adversary between communicating parties, making strong endpoint authentication important.
Encryption provides confidentiality but does not by itself prove who the communicating party is.
Pass-the-hash attacks reuse password-derived authentication material without necessarily recovering the plaintext password.
Kerberos attacks can target tickets, service credentials, privileged secrets and trust relationships rather than the cryptographic algorithm itself.
A stolen Kerberos ticket can become reusable authentication material.
Ransomware frequently uses encryption maliciously to deny availability and may additionally steal information for extortion.
Protected and regularly tested backups are critical to ransomware resilience.
The most important architectural lesson is that attackers normally choose the easiest path.
If breaking the cipher is extremely difficult but stealing the key, reusing a credential or exploiting an implementation is easy, the attacker will target the weaker part of the system.
Protect the algorithm, implementation, keys, protocols, credentials and surrounding architecture - not just the ciphertext.
๐ Sources & Further Reading Cryptanalysis, implementation attacks and defensive guidance
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-57 Part 1 Rev. 5 - Recommendation for Key Management
View NIST cryptographic and key-management guidance - NIST CSRC - Cryptanalysis
View the NIST cryptanalysis definition - NIST CSRC - Side-Channel Attack
View NIST side-channel terminology - NIST CSRC - Man-in-the-Middle Attack
View NIST MITM terminology - MITRE ATT&CK - Pass the Hash
View Pass-the-Hash defensive reference - MITRE ATT&CK - Steal or Forge Kerberos Tickets
View Kerberos attack concepts - MITRE ATT&CK - Data Encrypted for Impact
View ransomware encryption-for-impact reference - CISA - #StopRansomware Guide
View ransomware prevention and recovery guidance
