Netinfo Security ›› 2018, Vol. 18 ›› Issue (11): 73-80.doi: 10.3969/j.issn.1671-1122.2018.11.010

• 技术研究 • Previous Articles     Next Articles

Analysis of Data Hijacking in Instant Communication Network

Qingjun YUAN1, Siqi LU1,2(), Zhongxing WEI1, Jie GOU3   

  1. 1. PLA University of Information Engineering, Zhengzhou Henan 450000, China
    2. State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    3. 31011 PLA Troops, Beijing 100093, China
  • Received:2018-04-15 Online:2018-11-10 Published:2020-05-11

Abstract:

Data hijacking is an important means to intercept and analyze packets in instant messaging network, which seriously threatens the security of instant messaging network. Aiming at the security theory and data protection mechanism in instant messaging network, this paper analyzes the encryption and decryption operation of communication data and its protection mechanism by combining static disassembly with dynamic debugging. The analysis results show that the protection mechanism of IM network is defective and easy to be hijacked by internal users. Internal users can analyze communication data, guess packet composition, communication mechanism and encryption mechanism, obtain key parameters, restore system key, intercept software to decrypt key code, write communication data decryption program, obtain secret information transmitted by other users in the communication network, then tamper with communication information, and destroy the confidentiality, availability and controllability of the communication network.

Key words: instant messaging network, data hijacking, internal adversary

CLC Number: