SSC2 (Zheng, Carroll, Chan, FSE'00) ia a fast word-oriented software stream
cipher with two components, a nonlinear filter LFSR generator and a Lagged
Fibonacci generator. Three streams (two from the LFG) of output words are
combined to form the output keystream. Correlations and statistical
weaknesses for all three component streams are shown, as well as two
related attacks, which focus on the least significant bit of output words,
and distinguish the output of SSC2 from random with 2^22 and 2^46 words of
output respectively.