Application-based TCP hijacking

Application-based TCP hijacking
复制标题

基于应用程序的 TCP 劫持

DOI:
--
复制
发表时间:
2009
期刊:
European Workshop on System Security
影响因子:
--
通讯作者:
K. Beznosov
K. Beznosov
中科院分区:
--
文献类型:
--
作者:
Oliver Zheng;Jason Poon;K. Beznosov

文献摘要

被引文献

相似文献

我们提出了一种基于应用的TCP劫持(ABTH),这是一种针对TCP应用的新攻击,它利用由于TCP和应用协议之间的相互作用而产生的缺陷,在服务器或客户端应用程序都不会注意到欺骗攻击的情况下,将数据注入应用程序会话。在注入TCP包之后,ABTH会重新同步服务器和客户端的TCP堆栈。为了评估ABTH的可行性和有效性,我们开发了一个工具,可以在几秒钟内模拟Windows Live Messenger用户。由于其通用性,ABTH可以安装在各种现代协议上,用于基于TCP的应用程序。阻碍和/或限制ABTH有效性的对策可能包括严格的以太网交换和对消息的加密保护。然而,前者无法得到应用程序提供商的保证,而后者对于像Windows Live Messenger这样拥有数亿零星用户的大规模应用程序来说,似乎仍然昂贵得令人望而却步。
We present application-based TCP hijacking (ABTH), a new attack on TCP applications that exploits flaws due to the interplay between TCP and application protocols to inject data into an application session without either server or client applications noticing the spoofing attack. Following the injection of a TCP packet, ABTH resynchronizes the TCP stacks of both the server and the client. To evaluate the feasibility and effectiveness of ABTH, we developed a tool that allows impersonating users of Windows Live Messenger in the matter of few seconds. Due to its generic nature, ABTH can be mounted on a variety of modern protocols for TCP-based applications. Countermeasures to thwart and/or limit the effectiveness of ABTH could include strict Ethernet switching and cryptographic protection of messages. However, the former cannot be guaranteed by the application provider and the latter appears to be still prohibitively expensive for such large-scale applications with hundreds of millions of sporadic users as Windows Live Messenger.