ConMan: A Connection Manipulation-based Attack Against Bitcoin Networking

ConMan: A Connection Manipulation-based Attack Against Bitcoin Networking
复制标题

DOI:
10.1109/cns53000.2021.9705018
复制
发表时间:
2021-10
期刊:
2021 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Wenjun Fan;Sang-Yoon Chang;Xiaobo Zhou;Shouhuai Xu
Wenjun Fan;Sang-Yoon Chang;Xiaobo Zhou;Shouhuai Xu
中科院分区:
其他
文献类型:
--
作者:
Wenjun Fan;Sang-Yoon Chang;Xiaobo Zhou;Shouhuai Xu

文献摘要

被引文献

相似文献

比特币是一种代表性的加密货币系统,使用无许可的对等(P2P)网络作为其通信基础设施。在过去的几年里,已经发现了许多针对比特币的攻击,包括Eclipse和EREBUS攻击。在本文中,我们提出了一种针对比特币P2P网络的新攻击,称为ConMan,因为它利用了连接操纵。ConMan在隔离目标方面达到了与Eclipse和EREBUS攻击相同的效果(即,受害者)节点从比特币网络的其余部分。然而,ConMan与这些攻击不同,因为它是一种主动和确定性的攻击,并且更有效和高效。我们通过在一个与真实世界的比特币节点功能相结合的环境中进行概念验证来验证ConMan。实验结果表明,ConMan只需要几分钟就可以完全控制目标节点的对等连接,这与Eclipse和EREBUS攻击所需的数十天形成了鲜明对比。在此基础上,提出了几种针对ConMan的对策。其中一些是有效的,但与比特币的设计原则不兼容,而异常检测方法是可以实现的。我们向比特币核心团队披露了ConMan的情况,并收到了他们的反馈,这证实了ConMan和提出的对策。
Bitcoin is a representative cryptocurrency system using a permissionless peer-to-peer (P2P) network as its communication infrastructure. A number of attacks against Bitcoin have been discovered over the past years, including the Eclipse and EREBUS Attacks. In this paper, we present a new attack against Bitcoin’s P2P networking, dubbed ConMan because it leverages connection manipulation. ConMan achieves the same effect as the Eclipse and EREBUS Attacks in isolating a target (i.e., victim) node from the rest of the Bitcoin network. However, ConMan is different from these attacks because it is an active and deterministic attack, and is more effective and efficient. We validate ConMan through proof-of-concept exploitation in an environment that is coupled with real-world Bitcoin node functions. Experimental results show that ConMan only needs a few minutes to fully control the peer connections of a target node, which is in sharp contrast to the tens of days that are needed by the Eclipse and EREBUS Attacks. Further, we propose several countermeasures against ConMan. Some of them would be effective but incompatible with the design principles of Bitcoin, while the anomaly detection approach is positively achievable. We disclosed ConMan to the Bitcoin Core team and received their feedback, which confirms ConMan and the proposed countermeasures.