9. Informative References (资料性参考文献)
9. 资料性参考文献 (Informative References)
本节列出安全考虑事项写作指南的资料性背景文献. 这些文献涉及拒绝服务工具、密码认证密钥交换、Identification Protocol、Internet 认证、IPsec 问题区域、密码安全、NNTP、POP3、TCP 序列号弱点、SOAP、SRP、强制使用 IPsec 的指南以及 WEP 安全问题.
这些资料性文献用于提示 RFC 作者: 安全风险往往来自协议之外的部署环境和实现习惯. 密码选择、弱认证、无线链路加密、旧协议明文传输、序列号预测和拒绝服务工具都可能改变协议的实际风险面. 因此, 安全考虑事项不仅要描述协议机制本身, 还应说明实现者和部署者需要额外注意的条件.
[DDOS] "Denial-Of-Service Tools" CERT Advisory CA-1999-17, 28 December 1999, CERT http://www.cert.org/advisories/CA-1999-17.html
[EKE] Bellovin, S., Merritt, M., "Encrypted Key Exchange: Password-based protocols secure against dictionary attacks", Proceedings of the IEEE Symposium on Research in Security and Privacy, May 1992.
[IDENT] St. Johns, M. and M. Rose, "Identification Protocol", RFC 1414, February 1993.
[INTAUTH] Haller, N. and R. Atkinson, "On Internet Authentication", RFC 1704, October 1994.
[IPSPPROB] Bellovin, S. M., "Problem Areas for the IP Security Protocols", Proceedings of the Sixth Usenix UNIX Security Symposium, July 1996.
[KLEIN] Klein, D.V., "Foiling the Cracker: A Survey of and Improvements to Password Security", 1990.
[NNTP] Kantor, B. and P. Lapsley, "Network News Transfer Protocol", RFC 977, February 1986.
[POP] Myers, J. and M. Rose, "Post Office Protocol - Version 3", STD 53, RFC 1939, May 1996.
[SEQNUM] Morris, R.T., "A Weakness in the 4.2 BSD UNIX TCP/IP Software", AT&T Bell Laboratories, CSTR 117, 1985.
[SOAP] Box, D., Ehnebuske, D., Kakivaya, G., Layman, A., Mendelsoh, N., Nielsen, H., Thatte, S., Winer, D., "Simple Object Access Protocol (SOAP) 1.1", May 2000.
[SPEKE] Jablon, D., "Strong Password-Only Authenticated Key Exchange", Computer Communication Review, ACM SIGCOMM, vol. 26, no. 5, pp. 5-26, October 1996.
[SRP] Wu T., "The Secure Remote Password Protocol", ISOC NDSS Symposium, 1998.
[USEIPSEC] Bellovin, S., "Guidelines for Mandating the Use of IPsec", Work in Progress.
[WEP] Borisov, N., Goldberg, I., Wagner, D., "Intercepting Mobile Communications: The Insecurity of 802.11", http://www.isaac.cs.berkeley.edu/isaac/wep-draft.pdf