Towards Illuminating a Censorship Monitor's Model to Facilitate Evasion

Towards Illuminating a Censorship Monitor's Model to Facilitate Evasion
复制标题

阐明审查监督模式以促进逃避

DOI:
--
复制
发表时间:
2013
期刊:
IEEE Symposium on Foundations of Computational Intelligence
影响因子:
--
通讯作者:
V. Paxson
V. Paxson
中科院分区:
--
文献类型:
--
作者:
Sheharbano Khattak;M. Javed;Philip D. Anderson;V. Paxson

文献摘要

被引文献

相似文献

做出动态屏蔽决策的审查系统必须实时检查网络活动,以识别要过滤的内容。通过推断这些监视器的分析模型,我们可以识别它们对不同形式的规避的脆弱性,然后我们可以利用这些漏洞进行规避。我们利用的观察,审查监视器基本上工作在相同的原则,网络入侵检测系统(NIDS),因此继承了相同的规避漏洞已经讨论了多年的NIDS的上下文中。以过去的工作为指导,我们通过进行广泛的探测来测试中国防火长城的漏洞,说明了照亮监视器分析模型的力量。我们在其TCB创建和销毁、片段和段重组、数据包验证、HTTP分析的完整性和状态管理中发现了可利用的缺陷。
Censorship systems that make dynamic blocking decisions must inspect network activity on-the-fly to identify content to filter. By inferring the analysis models of such monitors we can identify their vulnerabilities to different forms of evasions that we can then exploit for circumvention. We leverage the observation that censorship monitors essentially work on the same principles as Network Intrusion Detection Systems (NIDS) and therefore inherit the same evasion vulnerabilities already discussed in the NIDS context for years. Using this past work as a guide, we illustrate the power of illuminating a monitor’s analysis model by conducting extensive probing to test for vulnerabilities in the Great Firewall of China. We find exploitable flaws in its TCB creation and destruction, fragment and segment reassembly, packet validation, (in)completeness of HTTP analysis, and state management.