Padlock
The CPNI has raised questions over the security of the TCP/IP system

Brits blast TCP/IP security

Report questions safety at the heart of the web

Written by Shaun Nichols in San Francisco

A report from a top UK government defence body is calling into question the security of the basic internet protocol.

The TCP/IP protocol is the basic function used by computers to communicate with outside networks. First adopted in 1983, the TCP/IP system is widely credited with enabling the creation of the internet as we know it.

The same protocol that enables the internet, however, may also be leaving it at risk, according to the Centre for Protection of the National Infrastructure (CPNI)

The company notes that many of the same techniques first used to link up the Arpanet network in 1983 are still in use today by the modern-day internet, and not all of them are secure.

"While many textbooks and articles have created the myth that the Internet Protocols were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the Arpanet, " read the introduction to the report.

"As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications. "

The CPNI noted that over the years vulnerabilities have emerged in everything from the handling of headers to dealing with fragments of code and reassembling data.

Even when those problems are patched, the CPNI pointed out that the fixes are not always approved or recommended by the Internet Engineering Task Force.

"In many cases vendors have implemented quick 'fixes' to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability," the report read.

"As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past."

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Vint Cerf

ITC makes Vint Cerf an Honorary Freeman

'Father of the internet' receives prestigious awards 18 Apr 2008

 

Internet heading for a fall, says founder

Arpanet scientist warns of coming network crunch 29 Oct 2007

Social effects of the web still unclear

Decades before we fully understand the impact, says Vint Cerf 04 Dec 2007

Microsoft kills Windows for Workgroups 3.11

Another operating system bites the dust 11 Jul 2008

National security at risk through connected IT systems

Elements of national infrastructure continue to be attacked electronically, says government 08 Aug 2008

Gates and co demand Manhattan project for energy

America's top business leaders launch American Energy Innovation Council with calls for increased investment in energy R&D 14 Jun 2010

Clubs under pressure as HMRC blows the whistle

FDs lose out in boardroom battles as football clubs forget the lessons from previous administrations 18 Feb 2010

Airport scanners are illegal, says human rights body

Equality and Human Rights Commission says scanners conflict with equality legislation 16 Feb 2010

related white papers

today's top stories

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Genuinely intuitive technology is years away

If the aim of technology is to simplify our lives, then it has failed 07 Sep 2010

Samsung P580 business laptop review

Not the most attractive business machine, but it's robust and performs well 06 Sep 2010

NAO urged to investigate £550m NPfIT contract

MP suspects BT deal represents very poor value for money 06 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

ShanghaiAnalysis

How tech companies can crack China

Having a good product will only get you so far, as Rachel Fielding explains 07 Sep 2010

HandshakeFeatures

The pros and cons of output-based contracting

Proponents of output-based contracting say it enables more efficient service delivery, innovation and an improved customer experience. But it needs to be approached with care 07 Sep 2010

Primary Navigation