Weaponizing Middleboxes for TCP Reflected Amplification

Weaponizing Middleboxes for TCP Reflected Amplification
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Kevin Bock;Abdulrahman Alaraj;Yair Fax;K. Hurley;Eric Wustrow;Dave Levin
Kevin Bock;Abdulrahman Alaraj;Yair Fax;K. Hurley;Eric Wustrow;Dave Levin
中科院分区:
其他
文献类型:
--
作者:
Kevin Bock;Abdulrahman Alaraj;Yair Fax;K. Hurley;Eric Wustrow;Dave Levin

文献摘要

被引文献

相似文献

反向放大攻击是DDoS攻击者武器库中的强大工具,但迄今为止几乎只针对基于UDP的协议。在本文中,我们证明了非平凡的基于TCP的放大是可能的,并且可以比众所周知的基于UDP的放大更有效。通过利用网络中间盒中的TCP不合规性,我们证明了攻击者可以诱导中间盒做出响应并放大网络流量。通过最近的遗传算法的新应用,我们发现并最大限度地提高了新的基于TCP的反射放大攻击的效率,并提出了几个数据包序列,导致网络中间盒响应的数据包远远多于我们发送的数据包。我们扫描了整个IPv4互联网,以测量有多少IP地址允许反射放大。我们发现数十万个IP地址提供大于100倍的放大系数。通过我们在互联网范围内的测量,我们探索了有关拒绝服务攻击的几个开放问题,包括所谓的“巨型放大器”的根本原因。我们还报告了一些网络现象,这些现象导致一些基于TCP的攻击非常有效,以至于在技术上具有无限放大因子(在攻击者发送恒定数量的字节后,反射器会无限地生成流量)。我们已经公开了我们的代码。
Reflective amplification attacks are a powerful tool in the arsenal of a DDoS attacker, but to date have almost exclusively targeted UDP-based protocols. In this paper, we demonstrate that non-trivial TCP-based amplification is possible and can be orders of magnitude more effective than well-known UDP-based amplification. By taking advantage of TCP-non-compliance in network middleboxes, we show that attackers can induce middleboxes to respond and amplify network traf-fic. With the novel application of a recent genetic algorithm, we discover and maximize the efficacy of new TCP-based reflective amplification attacks, and present several packet sequences that cause network middleboxes to respond with substantially more packets than we send. We scanned the entire IPv4 Internet to measure how many IP addresses permit reflected amplification. We find hundreds of thousands of IP addresses that offer amplification factors greater than 100 × . Through our Internet-wide measurements, we explore several open questions regarding DoS attacks, including the root cause of so-called “mega amplifiers”. We also report on network phenomena that causes some of the TCP-based attacks to be so effective as to technically have infinite amplification factor (after the attacker sends a constant number of bytes, the reflector generates traffic indefinitely). We have made our code publicly available.