SICO: Surgical Interception Attacks by Manipulating BGP Communities

SICO: Surgical Interception Attacks by Manipulating BGP Communities
复制标题

SICO:通过操纵 BGP 社区进行外科手术式拦截攻击

DOI:
10.1145/3319535.3363197
复制
发表时间:
2019
期刊:
2019 ACM SIGSAC Conference on Computer and Communications Security CCS.
影响因子:
--
通讯作者:
Mittal, Prateek
Mittal, Prateek
中科院分区:
--
文献类型:
--
作者:
Birge-Lee, Henry;Wang, Liang;Rexford, Jennifer;Mittal, Prateek

文献摘要

参考文献

被引文献

相似文献

边界网关协议BGP (Border Gateway Protocol)是互联网骨干网的主要路由协议,但它缺乏足够的安全机制。虽然简单的BGP劫持攻击只涉及攻击者劫持指向受害者的互联网流量,但更复杂和更具挑战性的拦截攻击需要攻击者拦截受害者的流量并将其转发给受害者。如果不正确地发起拦截攻击,攻击者的攻击将中断到受害者的路由,使数据包无法转发。为了克服这些挑战,我们引入了SICO攻击(使用社区的外科手术式拦截):一种利用BGP社区来确定对手攻击范围并确保通往受害者的路由的新型拦截攻击方法。然后,我们展示了SICO攻击如何针对特定的源IP地址以降低攻击成本。此外,我们在真实的互联网骨干网上道德地执行SICO攻击,以评估其可行性和有效性。结果表明,SICO攻击即使在先前提出的攻击不可行的情况下也能实现拦截,并且通过从额外的16%的互联网主机(最坏情况)和58%的互联网主机(最佳情况)吸引流量而优于它们。最后,我们分析了Internet拓扑结构,发现至少83%的多归属网络能够发起这些攻击。
The Border Gateway Protocol (BGP) is the primary routing protocol for the Internet backbone, yet it lacks adequate security mechanisms. While simple BGP hijack attacks only involve an adversary hijacking Internet traffic destined to a victim, more complex and challenging interception attacks require that adversary intercept a victim's traffic and forward it on to the victim. If an interception attack is launched incorrectly, the adversary's attack will disrupt its route to the victim making it impossible to forward packets. To overcome these challenges, we introduce SICO attacks (Surgical Interception using COmmunities): a novel method of launching interception attacks that leverages BGP communities to scope an adversary's attack and ensure a route to the victim. We then show how SICO attacks can be targeted to specific source IP addresses for reducing attack costs. Furthermore, we ethically perform SICO attacks on the real Internet backbone to evaluate their feasibility and effectiveness. Results suggest that SICO attacks can achieve interception even when previously proposed attacks would not be feasible and outperforms them by attracting traffic from an additional 16% of Internet hosts (worst case) and 58% of Internet hosts (best case). Finally, we analyze the Internet topology to find that at least 83% of multi-homed ASes are capable of launching these attacks.
BGP 社区:路由中存在更多蠕虫
DOI: 10.1145/3278532.3278557
发表时间: 2018
期刊: Proceedings of the Internet Measurement Conference 2018
影响因子: --
作者:
Florian Streibelt;F. Lichtblau;Robert Beverly;A. Feldmann;C. Pelsser;Georgios Smaragdakis;R. Bush
通讯作者: R. Bush
Counter-RAPTOR:保护 Tor 免受主动路由攻击
DOI: 10.1109/sp.2017.34
发表时间: 2017
期刊: 2017 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者:
Yixin Sun;A. Edmundson;N. Feamster;M. Chiang;Prateek Mittal
通讯作者: Prateek Mittal
DOI: --
发表时间: 2015
期刊:
影响因子: --
作者:
C. Dietzel;J. Snijders;Thomas King;G. Doering;Greg Hankins
通讯作者: Greg Hankins
Stellar:使用高级黑洞缓解网络攻击
DOI: --
发表时间: 2018
期刊: Conference on Emerging Network Experiment and Technology
影响因子: --
作者:
C. Dietzel;Georgios Smaragdakis;M. Wichtlhuber;A. Feldmann
通讯作者: A. Feldmann
NOPEER 边界网关协议 (BGP) 路由范围控制社区
DOI: --
发表时间: 2004
期刊: Request for Comments
影响因子: --
作者:
G. Huston
通讯作者: G. Huston