Static Detection of Packet Injection Vulnerabilities: A Case for Identifying Attacker-controlled Implicit Information Leaks

Static Detection of Packet Injection Vulnerabilities: A Case for Identifying Attacker-controlled Implicit Information Leaks
复制标题

DOI:
10.1145/2810103.2813643
复制
发表时间:
2015-10
期刊:
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Qi Alfred Chen;Zhiyun Qian;Yunhan Jia;Yuru Shao;Z. Morley Mao
Qi Alfred Chen;Zhiyun Qian;Yunhan Jia;Yuru Shao;Z. Morley Mao
中科院分区:
其他
文献类型:
--
作者:
Qi Alfred Chen;Zhiyun Qian;Yunhan Jia;Yuru Shao;Z. Morley Mao

文献摘要

被引文献

相似文献

路径外数据包注入攻击仍然是对互联网和网络安全的严重威胁。近年来,许多研究发现了数据包注入攻击的新变体,针对 TCP 等关键协议。我们认为,此类反复出现的问题需要系统的解决方案。在本文中,我们设计并实现了PacketGuardian,这是一种精确的静态污点分析工具,可以全面检查各种网络协议实现的数据包处理逻辑。分析分两步进行。首先,它确定导致接受传入数据包的关键路径和约束。如果存在弱约束的路径,则漏洞可能会立即暴露。否则,基于约束中的“秘密”协议状态,执行后续分析以检查这些状态是否可以泄露给攻击者。在第二步中,观察到所有先前报告的泄漏都是通过隐式流进行的,我们的工具支持隐式流污染,这是一个通常被排除的功能,因为它会引起大量的误报。为了应对这一挑战,我们提出了攻击者控制的隐式信息泄漏的概念,并优先使用我们的工具来检测它们,这在不影响工具有效性的情况下有效减少了误报。我们在 TCP、SCTP、DCCP 和 RTP 的 6 种流行协议实现上使用 PacketGuardian,并发现了 Linux 内核 TCP 以及三分之二的 RTP 实现中的新漏洞。我们验证了这些漏洞并确认它们确实具有高度可利用性。
Off-path packet injection attacks are still serious threats to the Internet and network security. In recent years, a number of studies have discovered new variations of packet injection attacks, targeting critical protocols such as TCP. We argue that such recurring problems need a systematic solution. In this paper, we design and implement PacketGuardian, a precise static taint analysis tool that comprehensively checks the packet handling logic of various network protocol implementations. The analysis operates in two steps. First, it identifies the critical paths and constraints that lead to accepting an incoming packet. If paths with weak constraints exist, a vulnerability may be revealed immediately. Otherwise, based on "secret" protocol states in the constraints, a subsequent analysis is performed to check whether such states can be leaked to an attacker. In the second step, observing that all previously reported leaks are through implicit flows, our tool supports implicit flow tainting, which is a commonly excluded feature due to high volumes of false alarms caused by it. To address this challenge, we propose the concept of attacker-controlled implicit information leaks, and prioritize our tool to detect them, which effectively reduces false alarms without compromising tool effectiveness. We use PacketGuardian on 6 popular protocol implementations of TCP, SCTP, DCCP, and RTP, and uncover new vulnerabilities in Linux kernel TCP as well as 2 out of 3 RTP implementations. We validate these vulnerabilities and confirm that they are indeed highly exploitable.