3.7 Cryptanalytic Attacks

CISSP Domain 3 ยท Security Architecture and Engineering

3.7 Cryptanalytic Attacks

Cryptanalytic attacks attempt to defeat cryptographic protection or exploit weaknesses in the way cryptographic and authentication systems are designed, implemented or used.

For CISSP, it is important to distinguish between attacks against the mathematics of cryptography and attacks against implementations, credentials, protocols or surrounding systems.

๐Ÿงฎ

Attack the Cipher

Analyse ciphertext, known information or the key space.

CRYPTOANALYSIS
โš™๏ธ

Attack the Implementation

Exploit timing, physical leakage, faults or programming weaknesses.

IMPLEMENTATION
๐ŸŽญ

Attack the Trust

Abuse credentials, tickets, protocols or communication relationships.

AUTHENTICATION

The Big Idea

A cryptographic algorithm can be mathematically strong while the overall system remains vulnerable.

An attacker may try several completely different approaches.

๐Ÿ”‘ Key โ†’ Can I guess or recover it?
๐Ÿ“„ Data โ†’ Can I learn patterns from plaintext or ciphertext?
โš™๏ธ Implementation โ†’ Does the software leak something useful?
โšก Hardware โ†’ Can physical behaviour reveal a secret?
๐ŸŒ Protocol โ†’ Can I intercept or manipulate communication?
๐ŸŽŸ๏ธ Credential โ†’ Can I reuse authentication material without breaking crypto?

Cryptanalytic Attack Memory Aid

BREAK The mathematics
GUESS The key
OBSERVE The implementation
MANIPULATE The system
STEAL The authentication material

Attackers do not have to break the cipher if there is an easier way.

CISSP 3.7 Scope

Attacks You Need to Recognise

AttackMain Idea
Brute ForceTry possible keys or credentials until one works.
Ciphertext-OnlyAnalyse encrypted information without knowing the plaintext.
Known-PlaintextUse known plaintext/ciphertext relationships to learn about the cryptosystem.
Frequency AnalysisUse statistical patterns in encrypted information.
Chosen-CiphertextObserve how selected ciphertext is processed or decrypted.
Implementation AttackExploit how cryptography was implemented rather than its mathematics.
Side-ChannelLearn secrets from indirect physical or computational leakage.
Fault InjectionInduce errors and analyse resulting behaviour.
Timing AttackLearn secrets from differences in execution time.
Man-in-the-MiddleIntercept and potentially alter communications between parties.
Pass-the-HashReuse captured password-hash-derived authentication material.
Kerberos ExploitationAbuse tickets, keys, accounts or Kerberos trust relationships.
RansomwareUse malware, often including encryption, to deny access and extort the victim.
๐Ÿ’ช Brute-Force Attack Try possibilities until the correct value is found

A brute-force attack attempts possible values until the correct key, password or other secret is discovered.

Brute force does not require finding a mathematical weakness in the algorithm.
Candidate 1 โ†’ Wrong
Candidate 2 โ†’ Wrong
Candidate 3 โ†’ Wrong
... โ†’ Continue searching
Correct Candidate โ†’ Success

What Makes Brute Force Difficult?

Large Key Space

More possible keys require more attempts.

High Entropy

Unpredictable secrets reduce useful shortcuts.

Slow Password Derivation

Appropriate password hashing makes each password guess more expensive.

Rate Limiting

Online systems can restrict repeated authentication attempts.

Key-space concept

A well-generated cryptographic key with a sufficiently large key space may make exhaustive search computationally impractical.

A human-selected password may have far less effective entropy, even if the underlying encryption algorithm is strong.

Brute force โ‰  cryptographic weakness

The algorithm may be working exactly as designed.

The attacker is simply testing possibilities.

Brute Force

NO SHORTCUT Try possibilities
DEFENCE Make the search space impractical
๐Ÿ” Ciphertext-Only Attack The attacker initially has only encrypted information

In a ciphertext-only attack, the attacker has one or more ciphertexts and attempts to derive useful information about the plaintext or cryptographic key.

Attacker Knows โ†’ CIPHERTEXT
Attacker Wants โ†’ PLAINTEXT or KEY
This is the most restrictive classical attack model

The attacker has less information than in known-plaintext or chosen input attacks.

Conceptual example

An attacker intercepts many encrypted messages but has no confirmed copy of the corresponding plaintext.

They analyse the ciphertext looking for exploitable patterns or weaknesses.

๐Ÿ“„ Known-Plaintext Attack The attacker knows some plaintext and its corresponding ciphertext

A known-plaintext attack assumes the attacker possesses examples of plaintext together with the corresponding ciphertext.

Known โ†’ PLAINTEXT
Known โ†’ MATCHING CIPHERTEXT
Analyse Relationship โ†’ Learn about key or cryptosystem
Conceptual example

An attacker knows that a standard message header appears in a particular encrypted message.

They therefore possess part of the plaintext and its encrypted equivalent.

Known plaintext โ‰  known key

The attacker knows some message content.

The purpose of the attack may still be to recover key material or decrypt other information.

๐ŸŽฏ Chosen-Ciphertext Attack The attacker can select ciphertext and observe how it is processed

In a chosen-ciphertext attack, an attacker is able to submit selected ciphertext values to a system and obtain information about the resulting decryption or observable behaviour.

Attacker Chooses โ†’ CIPHERTEXT
System โ†’ Processes / decrypts it
Attacker Observes โ†’ Result or behaviour
Repeated Analysis โ†’ Learn protected information
The system can accidentally become an oracle

Error messages, response differences or other observable behaviour may reveal information about protected data.

๐Ÿ“ Chosen-Plaintext Attack A useful comparison with the current CISSP attack models

In a chosen-plaintext attack, an attacker can select plaintext values and obtain their corresponding ciphertext.

Although chosen plaintext is not separately listed in the current CISSP 3.7 bullet list, understanding it makes the attack models easier to compare.

Attacker Chooses โ†’ PLAINTEXT
System Encrypts โ†’ CIPHERTEXT
Attacker Analyses โ†’ Relationship
Critical Comparison

What Does the Attacker Know?

AttackAttacker HasEasy Memory Aid
Ciphertext-OnlyCiphertext onlySEE ciphertext
Known-PlaintextKnown plaintext + corresponding ciphertextKNOW plaintext
Chosen-PlaintextAbility to choose plaintext and observe ciphertextCHOOSE plaintext
Chosen-CiphertextAbility to choose ciphertext and observe decryption behaviourCHOOSE ciphertext

Classical Attack Shortcut

CIPHERTEXT-ONLY I only SEE encrypted data
KNOWN-PLAINTEXT I KNOW some message content
CHOSEN-PLAINTEXT I CHOOSE what gets encrypted
CHOSEN-CIPHERTEXT I CHOOSE what gets decrypted
๐Ÿ“Š Frequency Analysis Use statistical patterns to infer information

Human languages and many forms of structured information contain statistical patterns.

Frequency analysis attempts to identify relationships between those patterns and encrypted symbols.

Classical cipher example

In English, some letters occur significantly more frequently than others.

If a simple substitution cipher maps the same plaintext letter to the same ciphertext symbol repeatedly, frequency patterns may remain visible.

Count Symbols โ†’ Find Patterns
Compare Statistics โ†’ Infer likely plaintext
Most relevant to classical cryptography

Properly designed modern cryptographic algorithms aim to eliminate exploitable statistical relationships between plaintext and ciphertext.

Frequency Analysis

COUNT Patterns
COMPARE Statistics
INFER Likely plaintext
โš™๏ธ Implementation Attacks Attack the implementation instead of the mathematical algorithm

A cryptographic algorithm can be mathematically secure while the software or hardware implementing it contains weaknesses.

Poor Randomness

Predictable keys or nonces can undermine otherwise strong cryptography.

Key Exposure

Secret material may be stored or handled insecurely.

Error Leakage

Different errors may reveal information about internal processing.

Memory Exposure

Sensitive keys may remain unnecessarily accessible in memory.

Side Channels

Physical or computational behaviour may leak information.

Protocol Mistakes

Secure primitives may be combined incorrectly.

Concept

An attacker does not break AES.

Instead, they discover that the application stores the AES key in an unprotected configuration file.

The cryptographic algorithm remains strong.

The implementation failed.

Implementation Attack

ALGORITHM May be strong
IMPLEMENTATION May still leak the secret
๐Ÿ“ก Side-Channel Attacks Observe something other than the intended cryptographic output

Side-channel attacks exploit information unintentionally leaked by the physical or computational behaviour of a cryptographic system.

Possible Side Channels

Timing

How long an operation takes.

Power Consumption

Changes in electrical power while processing.

Electromagnetic Emissions

Signals emitted by operating hardware.

Acoustic Leakage

Sounds produced during computation.

Cache Behaviour

Memory-access patterns observable through shared processor resources.

Physical Behaviour

Other measurable characteristics associated with computation.

Conceptual example

A cryptographic device uses slightly different amounts of power depending on operations involving secret key material.

Repeated measurements may reveal patterns correlated with the secret.

The mathematics may remain completely unbroken

The attacker is learning about the secret from how the cryptographic operation physically behaves.

Mitigations

Constant-Time Implementations Hardware Protection Masking Isolation Shielding Noise / Randomisation Implementation Testing

Side Channel

DO NOT Attack the cipher directly
OBSERVE How the system behaves
INFER The secret
โฑ๏ธ Timing Attacks A specific form of side-channel analysis

Timing attacks examine how long cryptographic or security operations take.

If processing time depends on secret information, repeated observations may reveal useful patterns.

Input A โ†’ 5.01 ms
Input B โ†’ 5.94 ms
Repeated Measurements โ†’ Statistical Difference
Difference โ†’ Potential information leakage
Timing attack = side-channel attack

Timing is a specific observable characteristic of the implementation.

Timing attack โ‰  measuring password lockout time

In cryptanalytic context, the key idea is that differences in processing duration reveal information about secret-dependent computation.

โšก Fault Injection Cause the system to make mistakes and analyse the result

Fault-injection attacks deliberately cause abnormal behaviour while a cryptographic device or security mechanism is operating.

The attacker then studies the faulty result or changed behaviour.

Normal Operation โ†’ Correct Output
Induced Fault โ†’ Abnormal Output
Compare Outputs โ†’ Infer information

Faults may be caused through environmental or physical manipulation of a device.

Mitigations

Fault Detection Redundant Calculations Integrity Checks Tamper Resistance Secure Failure Hardware Protection

Fault Injection

CAUSE An error
OBSERVE The faulty result
COMPARE With normal behaviour
๐Ÿ•ต๏ธ Man-in-the-Middle - MITM The attacker positions themselves between communicating parties

A Man-in-the-Middle attack places an attacker between communicating parties so communications can potentially be intercepted, relayed or modified.

Alice โ†’ ATTACKER
ATTACKER โ†’ Bob
Bob โ†’ ATTACKER
ATTACKER โ†’ Alice
Key-agreement example

Alice believes she is negotiating a secret directly with Bob.

Bob believes he is negotiating directly with Alice.

Without appropriate authentication, an attacker between them may establish separate relationships with both parties.

Encryption alone is not enough

Secure communication also needs appropriate authentication and integrity protection.

Mitigations

Authenticated Key Exchange Certificate Validation Mutual Authentication Integrity Protection Trusted PKI Secure Protocols

MITM

INTERCEPT Communication
IMPERSONATE Each side
DEFENCE Authenticate the endpoints
#๏ธโƒฃ Pass-the-Hash Reuse authentication material instead of cracking the password

Pass-the-hash attacks abuse authentication systems in which possession of a password-derived hash can be sufficient to authenticate.

The attacker does not necessarily need to recover the original plaintext password.
Password โ†’ Password-Derived Hash
Attacker Obtains Hash โ†’ Reuse Authentication Material
No Password Recovery โ†’ Still potentially authenticate
Pass-the-hash โ‰  password cracking

Password cracking attempts to determine the original password.

Pass-the-hash attempts to use the captured hash itself as authentication material.

Defensive Principles

Protect Credential Material Reduce Legacy Authentication Credential Isolation Least Privilege Privileged Account Separation Monitor Lateral Movement

Pass-the-Hash

DON'T CRACK The password
REUSE The hash
๐ŸŽŸ๏ธ Kerberos Exploitation Attack tickets, secrets and trust relationships

Kerberos uses tickets and symmetric cryptography to provide network authentication.

Attackers do not necessarily need to break the Kerberos cryptographic algorithms.

Instead, they may attempt to steal or abuse:

User Credentials Service Account Secrets Ticket-Granting Tickets Service Tickets Delegated Credentials Privileged Domain Secrets

Kerberos Refresher

User โ†’ Authentication Service
Authentication Service โ†’ Ticket-Granting Ticket - TGT
TGT โ†’ Ticket Granting Service
Ticket Granting Service โ†’ Service Ticket
Service Ticket โ†’ Application / Service

Attack Concepts Worth Recognising

Pass-the-Ticket

Reuse a stolen Kerberos ticket to access resources.

Ticket Theft

Obtain valid authentication tickets from a compromised system.

Weak Service Credentials

Poorly protected service secrets may create opportunities for credential attacks.

Forged Tickets

Compromise of critical Kerberos secrets can allow attackers to create fraudulent authentication tickets.

Delegation Abuse

Excessive or inappropriate delegation can increase the effect of credential compromise.

Privilege Concentration

Certain domain-level secrets have extremely high security value.

The ticket becomes the credential

If an attacker obtains appropriate authentication material, they may be able to impersonate the legitimate identity without knowing the user's password.

Defensive Principles

Protect Privileged Credentials Strong Service Account Secrets Managed Service Accounts Least Privilege Secure Delegation Credential Isolation Monitor Ticket Activity Protect Domain Controllers

Kerberos Attacks

TICKETS Are authentication material
KEYS Protect ticket trust
ATTACK Often steals trust rather than breaking crypto
๐Ÿฆ  Ransomware Cryptography used offensively to deny availability

Ransomware is malware designed to prevent organisations from accessing systems or information, commonly by encrypting files and demanding payment for restoration.

Cryptography itself is not malicious. Ransomware uses cryptographic capability for a malicious security objective.
Initial Compromise โ†’ Attacker gains access
Privilege / Movement โ†’ Expand impact
Data / Systems โ†’ Encrypt or disrupt
Organisation โ†’ Loses availability
Attacker โ†’ Demands payment

Double Extortion

Modern ransomware incidents may combine:

Encryption / Disruption

Prevent the victim from using systems or information.

Data Theft

Exfiltrate information and threaten disclosure.

Defensive Principles

Offline / Protected Backups Test Restoration Patch Management MFA Least Privilege Network Segmentation EDR Application Control Incident Response Security Monitoring
Backups must survive the attack

A backup that is continuously accessible from compromised systems may itself be deleted, altered or encrypted.

Ransomware

PRIMARY IMPACT Availability
MODERN IMPACT Availability + Confidentiality
RECOVERY Protected, tested backups
Connect the Concepts

What Is Actually Being Attacked?

TargetExamples
Key SpaceBrute force
Cipher RelationshipsCiphertext-only, known-plaintext, chosen-ciphertext, frequency analysis
ImplementationImplementation attacks, side channels
Physical BehaviourTiming, power analysis, fault injection
Communication TrustMan-in-the-Middle
Authentication MaterialPass-the-hash, Kerberos ticket exploitation
AvailabilityRansomware encryption for impact

Most Important Lesson

STRONG CIPHER Does not guarantee
STRONG SYSTEM if implementation or credentials are weak
Practical Scenario

A Strong Cipher, Weak Architecture

A banking application encrypts sensitive information using a strong modern cryptographic algorithm.

The security team identifies several problems.

Problem 1

Encryption keys are stored in plaintext configuration files.

Implementation / key-management weakness

Problem 2

Cryptographic processing time varies based on secret data.

Timing side channel

Problem 3

The application does not properly authenticate its key-exchange peer.

MITM risk

Problem 4

Privileged authentication material is exposed on compromised endpoints.

Credential reuse risk

Problem 5

Backups remain permanently writable from production.

Ransomware recovery risk

The encryption algorithm was never the problem

Security depends on the entire architecture surrounding the cryptographic primitive.

๐ŸŽ“ CISSP Scenarios Identify how the cryptographic system is being attacked
Scenario 1

An attacker tries every possible cryptographic key until readable plaintext is produced.

Attack?

Brute force.

Scenario 2

An attacker possesses only a collection of encrypted messages and attempts to recover their contents.

Attack model?

Ciphertext-only.

Scenario 3

An attacker knows that a specific encrypted message contains a standard document header.

Attack model?

Known-plaintext.

Scenario 4

An attacker can submit selected encrypted values to a system and observe differences in how they are processed.

Attack?

Chosen-ciphertext attack.

Scenario 5

An attacker analyses repeated symbols in a classical substitution cipher and compares them with common letter patterns.

Attack?

Frequency analysis.

Scenario 6

AES remains mathematically secure, but encryption keys are exposed through insecure application memory handling.

Attack category?

Implementation attack.

Scenario 7

An attacker observes a cryptographic device's electrical power use while it performs private-key operations.

Attack?

Side-channel attack.

Scenario 8

Differences in cryptographic processing duration correlate with secret values.

Attack?

Timing attack.

Scenario 9

An attacker deliberately causes a cryptographic device to produce abnormal results and compares them with normal results.

Attack?

Fault injection.

Scenario 10

Alice believes she has established a secure session with Bob, while an attacker has actually established separate sessions with both parties.

Attack?

Man-in-the-Middle.

Scenario 11

An attacker obtains password-derived authentication material and authenticates without first recovering the user's plaintext password.

Attack?

Pass-the-hash.

Scenario 12

A valid Kerberos ticket is stolen from a compromised system and later reused to access another service.

Attack concept?

Pass-the-ticket / Kerberos exploitation.

Scenario 13

A highly sensitive Kerberos domain secret is compromised, threatening the trust placed in authentication tickets.

What is the larger concern?

Compromise of the Kerberos trust infrastructure can enable fraudulent authentication.

Scenario 14

Malware encrypts production files and demands payment for restoration.

Attack?

Ransomware.

Scenario 15

Ransomware operators steal customer records before encrypting production systems and threaten to publish the records.

What is this commonly called?

Double extortion.

Scenario 16

A cryptographic system is resistant to mathematical attacks, but the CPU cache reveals secret-dependent memory-access patterns.

Attack category?

Side-channel / implementation attack.

Scenario 17

The security team proposes replacing a compromised cipher even though investigation shows the attacker simply stole the encryption key from an unprotected file.

What should the team focus on first?

Correct the key-management and implementation weakness.

Scenario 18

A key-agreement protocol is mathematically strong but does not authenticate either endpoint.

Which attack is particularly relevant?

Man-in-the-Middle.

CISSP Exam Perspective

Recognise the Clue Words

Try Every Key

Exhaustive search.

Brute Force

Only Encrypted Data

No known message content.

Ciphertext-Only

Know Some Message Content

Plaintext + matching ciphertext.

Known-Plaintext

Choose Encrypted Input

Observe decryption behaviour.

Chosen-Ciphertext

Statistical Patterns

Common symbols and language patterns.

Frequency Analysis

Strong Cipher, Bad Code

Implementation weakness.

Implementation Attack

Power / EM / Cache

Indirect leakage.

Side Channel

Processing Duration

Secret-dependent time differences.

Timing Attack

Induce Errors

Analyse faulty cryptographic output.

Fault Injection

Attacker Between Parties

Intercept or modify communication.

MITM

Reuse Hash

No plaintext password required.

Pass-the-Hash

Reuse Kerberos Ticket

Authentication ticket becomes the credential.

Pass-the-Ticket

Encrypt for Extortion

Availability impact.

Ransomware
โš ๏ธ Common CISSP Mistakes Understand what is actually being attacked
Brute Force โ‰  Cryptanalytic Breakthrough

Brute force may simply test the complete search space.

Ciphertext-Only โ‰  Known-Plaintext

Ciphertext-only means the attacker initially possesses only ciphertext.

Known-plaintext means some corresponding plaintext is already known.

Known Plaintext โ‰  Known Key

Knowing some original content does not mean the secret key is known.

Chosen-Ciphertext โ‰  Attacker Already Knows Plaintext

The attack gains information from how selected ciphertexts are processed.

Frequency Analysis โ‰  Brute Force

Frequency analysis exploits statistical patterns.

Brute force searches possible secrets.

Side Channel โ‰  Mathematical Cryptanalysis

The attacker observes implementation behaviour such as timing, power or electromagnetic leakage.

Timing Attack is a Side Channel

Timing is one specific form of observable implementation leakage.

Fault Injection โ‰  Passive Observation

The attacker actively induces abnormal behaviour and analyses the result.

Encryption โ‰  Authentication

A communication can be encrypted while still vulnerable to an attacker impersonating one of the endpoints.

Pass-the-Hash โ‰  Crack-the-Hash

Pass-the-hash reuses authentication material directly.

Kerberos Attack โ‰  Kerberos Cipher Broken

Many Kerberos attacks abuse stolen tickets, secrets, privileges or configuration rather than breaking the underlying cryptography.

Ransomware โ‰  Confidentiality Only

Encryption by ransomware primarily creates an availability problem, while data theft can additionally create a confidentiality breach.

Quick Reference

If you see...Think...
Try every possible keyBrute Force
Only encrypted messages availableCiphertext-Only
Some plaintext and ciphertext both knownKnown-Plaintext
Statistical letter or symbol patternsFrequency Analysis
Choose ciphertext and observe processingChosen-Ciphertext
Strong algorithm but weak softwareImplementation Attack
Power, EM, cache or acoustic informationSide Channel
Different execution times reveal informationTiming Attack
Deliberately induce incorrect cryptographic operationFault Injection
Attacker positioned between communicating partiesMITM
Reuse password hash rather than recover passwordPass-the-Hash
Reuse a Kerberos ticketPass-the-Ticket
Attack Kerberos keys, tickets or service identitiesKerberos Exploitation
Files encrypted and ransom demandedRansomware

Cryptanalytic Attack Master Memory Aid

BRUTE FORCE Try everything
CIPHERTEXT ONLY See encrypted data
KNOWN PLAINTEXT Know some original data
FREQUENCY Analyse patterns
CHOSEN CIPHERTEXT Choose what gets processed
SIDE CHANNEL Observe leakage
FAULT Cause errors
TIMING Measure time
MITM Stand between parties
PASS-THE-HASH Reuse hash
KERBEROS Attack tickets and trust
RANSOMWARE Encrypt for impact

The Easiest Way to Think About 3.7

MATH Ciphertext, plaintext, frequency, brute force
MACHINE Side channel, timing, fault injection
MIDDLE MITM
CREDENTIAL Pass-the-hash and Kerberos
IMPACT Ransomware

Math ยท Machine ยท Middle ยท Credential ยท Impact

Key Takeaways

Cryptanalysis attempts to defeat cryptographic protection or exploit weaknesses in cryptographic systems.

A secure algorithm does not guarantee a secure implementation.

Brute force tests possible keys or secrets rather than necessarily exploiting a weakness in the algorithm.

Ciphertext-only attacks begin with encrypted information and no confirmed corresponding plaintext.

Known-plaintext attacks use known plaintext/ciphertext relationships.

Chosen-ciphertext attacks allow the attacker to select ciphertext and learn from how the cryptographic system processes it.

Frequency analysis uses statistical patterns and is particularly associated with classical cryptographic systems.

Implementation attacks exploit weaknesses surrounding the algorithm rather than necessarily defeating its mathematics.

Side-channel attacks obtain information from characteristics such as execution time, power consumption, electromagnetic emissions, acoustic emissions or memory behaviour.

Timing attacks are a specific form of side-channel attack.

Fault-injection attacks deliberately create abnormal system behaviour and analyse the resulting output.

Man-in-the-Middle attacks place an adversary between communicating parties, making strong endpoint authentication important.

Encryption provides confidentiality but does not by itself prove who the communicating party is.

Pass-the-hash attacks reuse password-derived authentication material without necessarily recovering the plaintext password.

Kerberos attacks can target tickets, service credentials, privileged secrets and trust relationships rather than the cryptographic algorithm itself.

A stolen Kerberos ticket can become reusable authentication material.

Ransomware frequently uses encryption maliciously to deny availability and may additionally steal information for extortion.

Protected and regularly tested backups are critical to ransomware resilience.

The most important architectural lesson is that attackers normally choose the easiest path.

If breaking the cipher is extremely difficult but stealing the key, reusing a credential or exploiting an implementation is easy, the attacker will target the weaker part of the system.

Protect the algorithm, implementation, keys, protocols, credentials and surrounding architecture - not just the ciphertext.

๐Ÿ“š Sources & Further Reading Cryptanalysis, implementation attacks and defensive guidance