AI 中文总结
该研究提出域解耦攻击(DDA),利用DNS授权的验证间隙,在CDN及非CDN共享托管环境中可实现跨租户访问,测量显示高暴露率,揭示DNS访问控制的结构性局限,为访问控制机制改进提供依据。
AI 中文摘要
网络攻击者常将恶意通信隐藏在合法互联网流量中。现有基于CDN的规避技术依赖SNI-Host不一致性、不充分的域所有权验证或特定提供商的路由重写,这些技术在现代CDN环境中的适用性受限。我们发现了基于DNS的授权中的一个验证间隙:源自允许域的权限适用于共享IP,可在CDN及非CDN共享托管环境中被重用于访问另一租户。本文提出域解耦攻击(Domain Decoupling Attack,DDA),该方法解析允许域以获取共享边缘IP的权限,随后在TLS SNI和HTTP Host中一致呈现隐藏域的同时连接至同一地址。对六大洲1069048个域的测量产生了18025068次成功探测,确定总体暴露率为95.8%,CDN域暴露率为99.26%,非CDN域为92.75%,非CDN跨租户IP为97.7%;实验室实验揭示了共享地址上基于DNS的访问控制的结构性局限。这些结果阐明了源自DNS的IP授权的安全风险,为CDN及非CDN共享托管环境中访问控制机制的评估与改进提供支持。
英文摘要
Network attackers often conceal malicious communication within legitimate Internet traffic. Existing CDN-based evasion techniques rely on SNI--Host inconsistency, insufficient domain ownership verification, or provider-specific routing rewrites, which limit their applicability in modern CDN environments. We identify a validation gap in DNS-based authorization, where permission derived from an allowed domain applies to a shared IP and can be reused to reach another tenant in both CDN and non-CDN shared-hosting environments. This paper presents the Domain Decoupling Attack (DDA), which resolves an allowed domain to obtain permission for a shared edge IP and subsequently connects to the same address while presenting the hidden domain consistently in both TLS SNI and HTTP Host. Measurements of 1,069,048 domains across six continents produce 18,025,068 successful probes and identify exposure rates of 95.8% overall, 99.26% for CDN domains, 92.75% for non-CDN domains, and 97.7% for non-CDN cross-tenant IPs, while laboratory experiments reveal a structural limitation of DNS-bound access control on shared addresses. These results clarify the security risks of DNS-derived IP authorization and support the evaluation and improvement of access-control mechanisms in CDN and non-CDN shared-hosting environments.