Security Analysis of IRC Server Design: Mapping Protocol Features to Attack Vectors Using the MITRE ATT&CK Framework


Saritas M., Kaya Y. T., Malkawi M., Alhajj R.

34th IEEE International Requirements Engineering Conference Workshops, REW 2026, Montreal, Kanada, 17 - 21 Ağustos 2026, ss.162-169, (Tam Metin Bildiri)

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Doi Numarası: 10.1109/rew72749.2026.00033
  • Basıldığı Şehir: Montreal
  • Basıldığı Ülke: Kanada
  • Sayfa Sayıları: ss.162-169
  • Anahtar Kelimeler: Cybersecurity Education, IRC, MITRE ATT&CK, Network Security, Protocol Abuse, Threat Modeling
  • İstanbul Medipol Üniversitesi Adresli: Evet

Özet

Internet Relay Chat (IRC) server development remains a cornerstone of computer networking education. However, these academic practices often prioritize functional concurrency over defensive design, leading to an accumulation of security vulnerabilities. This paper analyzes how functionality-first designs unconsciously expose broad attack surfaces. Using the Microsoft Threat Modeling Tool (MTMT), we apply the STRIDE framework to IRC command flows (NICK, JOIN, PRIVMSG, LIST/NAMES). We then map the resulting architectural vulnerabilities to the MITRE ATT&CK framework. Our findings demonstrate that the absence of cryptographic authentication, strict state validation, and encryption transforms basic protocol operations into native vectors for masquerading (T1036), privilege elevation (T1548), command-and-control (T1071), and discovery activities (T1018/T1087). By demonstrating that educational networking projects across computing disciplines often share architectural similarities with real-world attack infrastructures, we highlight a significant gap in networking and cybersecurity education across the computing field. Consequently, we argue that threat modeling and secure design principles must be explicitly integrated into these assignments to align educational practices with real life cybersecurity requirements.