arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.09345cs.CR

跨用户/应用网络攻击——通过恶意用户/应用劫持TCP连接和DNS缓存投毒(扩展版)

Cross User/App Network Attacks - Hijacking TCP Connections and DNS Cache Poisoning via a Malicious User/App (Extended Version)

Tamir Shahar, Amit Klein

首次发表
浏览论文内容

中文总结 AI 辅助

本研究证明无特权恶意应用与远程攻击者协作,利用套接字API和系统特性推断TCP序列号及UDP端口,实现对多操作系统的连接劫持和DNS缓存投毒。

中文摘要 AI 辅助

针对TCP和DNS(基于UDP)客户端-服务器连接的路径外网络攻击,如今通常被认为是不切实际的,这得益于这些协议内置的安全特性,例如随机的TCP(初始)序列号和随机的UDP源端口。在本工作中,我们反驳了这一假设,通过证明运行在客户端上的一个无特权恶意应用(但实际上处于路径外),与远程路径外攻击者相结合,能够对此类连接发起强大的网络攻击。我们展示了这种恶意应用与远程攻击者之间的本地-远程协作如何允许推断敏感的连接状态,包括TCP序列号和DNS存根解析器的UDP源端口。我们的攻击利用标准套接字API调用(如bind())、协议机制(如IP选项)以及操作系统特性(如cBPF和procfs)来推断TCP初始序列号(ISN)和所关注连接正在使用的UDP源端口。具体来说,我们利用了主要操作系统中实现的ISN生成算法的某些特性。我们在Linux、Android、Windows、macOS和iOS上演示了TCP连接劫持,并针对Windows、Android以及Linux中流行的systemd-resolved DNS存根解析器演示了DNS缓存投毒。我们在多个操作系统和现实部署环境中评估了我们的技术,包括在保留端口的NAT集成路由器之后的环境。我们向微软、苹果、Linux和谷歌披露了我们的技术,这导致了多个补丁的发布。

英文摘要

Off-path network attacks against TCP and DNS (over UDP) client-server connections are generally considered impractical nowadays, due to built-in security features in these protocols, e.g. randomized TCP (initial) sequence numbers and randomized UDP source ports, respectively. In this work, we refute this presumption by demonstrating that an unprivileged malicious application running on the client (but practically off-path), when combined with a remote off-path adversary, can enable powerful network attacks against such connections. We show how such a local--remote collaboration between the malicious application and a remote adversary allows inference of sensitive connection state, including TCP sequence numbers and DNS stub-resolver UDP source ports. Our attacks exploit standard socket API calls such as bind(), protocol mechanisms such as IP options, and operating system features such as cBPF and procfs to infer the TCP initial sequence number (ISN) and the UDP source port in use by the connection of interest. Specifically, we take advantage of certain properties of the ISN generation algorithm as implemented in major operating systems. We demonstrate TCP connection hijacking in Linux, Android, Windows, macOS and iOS, and DNS cache poisoning against Windows, Android and the popular systemd-resolved DNS stub resolver in Linux. We evaluate our techniques across multiple operating systems and realistic deployment settings, including environments behind port-preserving NAT-integrated routers. We disclosed our techniques to Microsoft, Apple, Linux and Google, which led to the release of several patches.

发表机构

  • Hebrew University(希伯来大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑