Detecting TCP/IP Connections via IPID Hash Collisions

Detecting TCP/IP Connections via IPID Hash Collisions
复制标题

DOI:
10.2478/popets-2019-0071
复制
发表时间:
2019-07
影响因子:
--
通讯作者:
Geoffrey Alexander;Antonio M. Espinoza;Jedidiah R. Crandall
Geoffrey Alexander;Antonio M. Espinoza;Jedidiah R. Crandall
中科院分区:
--
文献类型:
--
作者:
Geoffrey Alexander;Antonio M. Espinoza;Jedidiah R. Crandall

文献摘要

相似文献

摘要本文提出了一种新的攻击方法,用于检测远程Linux服务器和任意客户机之间是否存在活动的TCP连接。该攻击利用了Linux内核处理用于填充IPv4数据包的IPID字段的值时存在的边通道,并适用于4.0及更高版本的内核。我们实现和测试这种攻击,并评估其真实的世界的有效性和性能时,使用的活跃连接到流行的Web服务器。我们的评估表明,攻击是能够正确地检测IP端口4元组代表一个活跃的TCP连接在我们的模拟攻击的84%。我们还演示了如何攻击可以使用的中间洋葱路由器在Tor电路测试是否一个给定的客户端连接到与给定的电路相关联的警卫入口节点。此外,我们还讨论了攻击者在尝试将其扩展到真实的世界攻击时可能面临的问题,以及针对攻击的可能缓解措施。我们的攻击不会耗尽任何全局资源,因此挑战了共享的有限资源和非平凡网络侧信道之间存在直接一对一连接的概念。这意味着简单地枚举全局共享资源并考虑它们可以被耗尽的方式将不足以证明内核TCP/IP网络栈没有隐私风险侧信道。
Abstract We present a novel attack for detecting the presence of an active TCP connection between a remote Linux server and an arbitrary client machine. The attack takes advantage of side-channels present in the Linux kernel’s handling of the values used to populate an IPv4 packet’s IPID field and applies to kernel versions of 4.0 and higher. We implement and test this attack and evaluate its real world effectiveness and performance when used on active connections to popular web servers. Our evaluation shows that the attack is capable of correctly detecting the IP-port 4-tuple representing an active TCP connection in 84% of our mock attacks. We also demonstrate how the attack can be used by the middle onion router in a Tor circuit to test whether a given client is connected to the guard entry node associated with a given circuit. In addition we discuss the potential issues an attacker would face when attempting to scale it to real world attacks, as well as possible mitigations against the attack. Our attack does not exhaust any global resource, and therefore challenges the notion that there is a direct one-to-one connection between shared, limited resources and non-trivial network side-channels. This means that simply enumerating global shared resources and considering the ways in which they can be exhausted will not suffice for certifying a kernel TCP/IP network stack to be free of privacy risk side-channels.