arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

不可达节点真的安全吗?完全遮蔽门罗币的P2P网络!

Are Unreachable Nodes Truly Safe? Fully Eclipsing Monero's P2P Network!

Ruisheng Shi, Jiaqi Zeng, Lina Lan, Shihan Zhang, Bing Han, Xiapu Luo, Qishu Jin, Wenliang Du, Qin Wang

arXiv 2609.10260首次发表:更新:

发表机构

Beijing University of Posts and Telecommunications; Hong Kong Polytechnic University; Zhejiang University; CSIRO(北京邮电大学; 香港理工大学; 浙江大学; 澳大利亚联邦科学与工业研究组织)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文挑战不可达节点更安全的假设,提出针对门罗币P2P网络中NAT后节点的首个遮蔽攻击,通过污染对等列表和利用出站连接刷新逻辑实现完全遮蔽,并经模拟和主网验证。

AI 中文摘要

遮蔽攻击通过垄断区块链节点的网络连接来隔离该节点。现有针对门罗币(NDSS'25)、比特币(USENIX'15/21, S&P'20)和以太坊(WWW'26)的攻击隐含假设攻击者能够建立入站连接,从而排除了大量且实际占主导地位的节点类别:位于NAT之后运行的\ extit{不可达节点}。这类节点被广泛认为享有更强的网络安全性。我们挑战这一假设,并表明不可达性并不意味着预期的韧性!我们提出了首个针对门罗币P2P网络中不可达节点的遮蔽攻击。我们的攻击无需对受害者进行入站访问。相反,它们首先污染可达节点的对等节点列表,这些节点随后充当传播中继,以污染不可达节点的白名单。攻击者随后利用门罗币内置的出站连接刷新逻辑来驱逐良性邻居,并最终垄断所有出站连接。我们将此策略实例化为两种攻击:Nyx,针对长期运行的不可达节点,通过网络范围的污染实现完全且持久的遮蔽;以及Moros,一种更隐蔽的攻击,利用引导阶段快速遮蔽新加入的不可达节点。我们以合乎道德的方式评估了这两种攻击。Nyx通过在SEED模拟器构建的门罗币网络上进行大规模模拟得到验证,而Moros则在门罗币主网上针对受控目标进行了演示。我们的结果表明,不可达节点可以被可靠地驱入稳定、长期的遮蔽状态。我们还提出了相应的对策。

英文摘要

Eclipse attacks isolate a blockchain node by monopolizing its network connections. Existing attacks on Monero (NDSS'25), Bitcoin (USENIX'15/21, S&P'20) and Ethereum (WWW'26) implicitly assume that the adversary can establish inbound connections, thereby excluding a large and practically dominant class of nodes: \textit{unreachable nodes} operating behind NATs. Such nodes are widely believed to enjoy stronger networks. We challenge this assumption and show that unreachability does NOT imply the expected resilience! We present the first eclipse attacks tailored to unreachable nodes in Monero's P2P network. Our attacks require no inbound access to the victim. Instead, they first poison the peerlist of reachable nodes, which subsequently act as propagation relays to contaminate unreachable nodes' whitelists. The adversary then exploits Monero's built-in outbound connection refresh logic to evict benign neighbors and eventually monopolize all outbound connections. We instantiate this strategy in two attacks: Nyx, which targets long-running unreachable nodes and achieves a complete and persistent eclipse through network-wide poisoning; and Moros, a stealthier attack that exploits the bootstrapping phase to rapidly eclipse newly joined unreachable nodes. We ethically evaluate both attacks. Nyx is validated via large-scale simulations on a Monero network constructed using the SEED Emulator, while Moros is demonstrated on the Monero mainnet against controlled targets. Our results show that unreachable nodes can be reliably driven into stable, long-lived eclipse states. We also propose countermeasures.

CommentsAccepted by ACM CCS'26 (The Hague, The Netherlands)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑