Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach

Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach
复制标题

DOI:
10.1145/3232755.3232769
复制
发表时间:
2018-07
期刊:
Proceedings of the Applied Networking Research Workshop
影响因子:
--
通讯作者:
Samuel Jero;Md. Endadul Hoque;D. Choffnes;A. Mislove;C. Nita-Rotaru
Samuel Jero;Md. Endadul Hoque;D. Choffnes;A. Mislove;C. Nita-Rotaru
中科院分区:
其他
文献类型:
--
作者:
Samuel Jero;Md. Endadul Hoque;D. Choffnes;A. Mislove;C. Nita-Rotaru

文献摘要

被引文献

相似文献

在这项工作中,我们提出了一种自动化的方法来发现针对TCP拥塞控制实现的攻击,该方法结合了实现无关模糊测试的通用性和运行时分析的准确性。它使用模型引导的方法生成抽象的攻击策略,方法是利用拥塞控制的状态机模型来查找易受攻击的状态机路径,攻击者可以利用这些路径来增加或减少连接的吞吐量。然后将这些抽象策略映射到具体的攻击策略,这些攻击策略由一系列动作组成,例如注入或修改确认。我们设计并实现了一个虚拟平台TCPwn,它包含一个基于代理的攻击注入器来注入这些具体的攻击策略。我们评估了来自4个Linux发行版和Windows 8.1的5个TCP实现。总的来说,我们发现了11类攻击,其中8种是新的。
In this work, we propose an automated method to find attacks against TCP congestion control implementations that combines the generality of implementation-agnostic fuzzing with the precision of runtime analysis. It uses a model-guided approach to generate abstract attack strategies by leveraging a state machine model of congestion control to find vulnerable state machine paths that an attacker could exploit to increase or decrease the throughput of a connection. These abstract strategies are then mapped to concrete attack strategies, which consist of sequences of actions such as injection or modification of acknowledgements. We design and implement a virtualized platform, TCPwn, that consists of a proxy-based attack injector to inject these concrete attack strategies. We evaluated 5 TCP implementations from 4 Linux distributions and Windows 8.1. Overall, we found 11 classes of attacks, of which 8 are new.