All the latest UK technology news, reviews and analysis

Brits blast TCP/IP security

by Shaun Nichols

More from this author

21 Aug 2008

Comments: 3

  • Tweet this
Padlock
The CPNI has raised questions over the security of the TCP/IP system

A report from a top UK government defence body is calling into question the security of the basic internet protocol.

The TCP/IP protocol is the basic function used by computers to communicate with outside networks. First adopted in 1983, the TCP/IP system is widely credited with enabling the creation of the internet as we know it.

The same protocol that enables the internet, however, may also be leaving it at risk, according to the Centre for Protection of the National Infrastructure (CPNI)

The company notes that many of the same techniques first used to link up the Arpanet network in 1983 are still in use today by the modern-day internet, and not all of them are secure.

"While many textbooks and articles have created the myth that the Internet Protocols were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the Arpanet, " read the introduction to the report.

"As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications. "

The CPNI noted that over the years vulnerabilities have emerged in everything from the handling of headers to dealing with fragments of code and reassembling data.

Even when those problems are patched, the CPNI pointed out that the fixes are not always approved or recommended by the Internet Engineering Task Force.

"In many cases vendors have implemented quick 'fixes' to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability," the report read.

"As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Technical Author

Technical Author - Word, Excel, Visio, Access - Cheltenham...

Java Developer

Java/J2EE Developer - St Albans - £35,000 - £40,000...

Business Analyst – Custody, Cash Management

Business Analyst – Custody, Cash Management Our...

Online Marketing Executive - PPC / SEO

A fantastic opportunity for an experienced Online Marketing...

To send to more than one email address, simply separate each address with a comma.