arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

跨越数据流:通过多路复用信道中的公共压缩上下文恢复 SSH 明文

Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels

Fabian Bäumer, Marcus Brinkmann

arXiv 2609.07709首次发表:更新:

AI 中文总结

本研究首次发现SSH信道多路复用共享压缩上下文导致压缩侧信道,提出自适应选择明文攻击,可在低噪声场景下用最多276次猜测恢复8字符秘密。

AI 中文摘要

SSH 是用于服务器安全远程管理的标准协议。在传输层,SSH 使用二进制包协议(BPP)进行加密和认证通信。在此之上,SSH 连接协议在单个连接上多路复用一条或多条逻辑信道,支持交互式 shell、端口转发及相关功能。我们发现 SSH 信道多路复用产生了一个此前未被识别的压缩侧信道:连接上的所有信道共享同一个压缩上下文。当启用压缩时,攻击者可以向一个信道注入部分选择的明文,并在网络上观察由此产生的密文长度。这使得自适应选择明文攻击能够通过与另一信道的交互来恢复一个信道中的秘密。虽然诸如 CRIME 和 BREACH 之类的相关攻击已在 TLS 上的 HTTP 场景中被广泛研究,但据我们所知,这是首次针对 SSH 的压缩侧信道攻击,也是首次在 SSH 分析中考虑结合被动窃听者和 Web 攻击者的威胁模型。我们进一步在三种不同的应用场景中演示了该攻击,并评估了其在不同协议噪声水平下的有效性。我们发现,在最低噪声场景中,一个 26 字母表上的 8 字符秘密最多使用 276 次猜测即可被恢复。最后,我们分析了 SSH 生态系统中影响攻击实际效力的压缩支持情况及其他实现特征。

英文摘要

SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, the SSH Connection Protocol multiplexes one or more logical channels over a single connection, supporting interactive shells, port forwarding, and related functionality. We show that SSH channel multiplexing creates a previously unrecognized compression side channel: all channels on a connection share the same compression context. When compression is enabled, an attacker can inject partially chosen plaintext into a channel and observe the length of the resulting ciphertext on the network. This enables an adaptive chosen-plaintext attack that recovers secrets from one channel by interacting with another. While related attacks such as CRIME and BREACH have been studied extensively for HTTP over TLS, this is, to our knowledge, the first compression side-channel attack on SSH and the first SSH analysis to consider a combined passive eavesdropper and web attacker threat model. We further demonstrate the attack in three different application scenarios and evaluate its effectiveness under varying levels of protocol noise. We find that, in the lowest-noise scenario, an 8-character secret over a 26-letter alphabet can be recovered using at most 276 guesses. Finally, we analyze the SSH ecosystem for compression support and other implementation characteristics that influence the practical efficacy of the attack.

Comments15 pages, 5 figures, accepted at ACM CCS 2026; v2: clarified "PrivX'' -> "PrivX Desktop'' in Table 4

DOI:10.1145/3830454.3846537

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑