TY - GEN
T1 - A proxy-based solution for securiting remote desktop connections in mission-critical systems
AU - Bitton, Ron
AU - Feher, Clint
AU - Elovici, Yuval
AU - Shabtai, Asaf
AU - Shugol, Gaby
AU - Tikochinski, Raz
AU - Kur, Shachar
N1 - Publisher Copyright: © 2017 IEEE.
PY - 2017/4/25
Y1 - 2017/4/25
N2 - Remote desktop protocols (RDPs) are used for connecting and interacting with computers remotely. In recent years, we have witnessed a number of vulnerabilities identified in two widely used remote desktop implementations, Microsoft Remote Desktop and RealVNC, that may expose the connected systems to a new attack vector. Such vulnerabilities are particularly concerning when it comes to mission-critical systems in which a client device with a low trust level connects to the critical system via a remote desktop server. In this preliminary study we propose a proxy-based solution that applies various modules, each of which mitigates a different type of threat, in order to secure remote desktop connections used in missioncritical systems.
AB - Remote desktop protocols (RDPs) are used for connecting and interacting with computers remotely. In recent years, we have witnessed a number of vulnerabilities identified in two widely used remote desktop implementations, Microsoft Remote Desktop and RealVNC, that may expose the connected systems to a new attack vector. Such vulnerabilities are particularly concerning when it comes to mission-critical systems in which a client device with a low trust level connects to the critical system via a remote desktop server. In this preliminary study we propose a proxy-based solution that applies various modules, each of which mitigates a different type of threat, in order to secure remote desktop connections used in missioncritical systems.
KW - Malware
KW - Mission-critical system
KW - Proxy
KW - Remote code execution
KW - Remote desktop
UR - http://www.scopus.com/inward/record.url?scp=85019203874&partnerID=8YFLogxK
U2 - 10.1109/HASE.2017.38
DO - 10.1109/HASE.2017.38
M3 - Conference contribution
T3 - Proceedings of IEEE International Symposium on High Assurance Systems Engineering
SP - 153
EP - 156
BT - Proceedings - IEEE 18th International Symposium on High Assurance Systems Engineering, HASE 2017
T2 - 18th IEEE International Symposium on High Assurance Systems Engineering, HASE 2017
Y2 - 12 January 2017 through 14 January 2017
ER -