论文标题

《银河系劫机者指南:外面接管互联网资源》

The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources

论文作者

Dai, Tianxiang, Jeitner, Philipp, Shulman, Haya, Waidner, Michael

论文摘要

互联网资源构成了数字社会的基本结构。它们为数字服务和资产提供了基本平台,例如关键基础设施,金融服务,政府。谁控制着有效控制数字社会的人。 在这项工作中,我们证明了互联网资源管理,IP地址,域,证书和虚拟平台的当前实践是不安全的。在长时间的时间里,对手可以保持对他们不拥有并进行隐秘操纵的互联网资源的控制,从而导致毁灭性的攻击。我们表明,网络对手可以接管并操纵至少68%的IPv4地址空间以及31%的Alexa域。我们通过劫持与数字资源相关的帐户来证明此类攻击。 对于劫持帐户,我们启动了DNS CACHE中毒攻击,以重定向密码恢复链接到对抗主机。然后,我们证明对手可以操纵与这些帐户相关的资源。我们发现所有经过攻击的测试提供者都容易受到攻击。 我们建议缓解阻止我们在这项工作中提出的攻击。然而,对策无法解决基本问题 - 应修订互联网资源的管理,以确保不能尽可能轻松而隐秘地进行交易。

Internet resources form the basic fabric of the digital society. They provide the fundamental platform for digital services and assets, e.g., for critical infrastructures, financial services, government. Whoever controls that fabric effectively controls the digital society. In this work we demonstrate that the current practices of Internet resources management, of IP addresses, domains, certificates and virtual platforms are insecure. Over long periods of time adversaries can maintain control over Internet resources which they do not own and perform stealthy manipulations, leading to devastating attacks. We show that network adversaries can take over and manipulate at least 68% of the assigned IPv4 address space as well as 31% of the top Alexa domains. We demonstrate such attacks by hijacking the accounts associated with the digital resources. For hijacking the accounts we launch off-path DNS cache poisoning attacks, to redirect the password recovery link to the adversarial hosts. We then demonstrate that the adversaries can manipulate the resources associated with these accounts. We find all the tested providers vulnerable to our attacks. We recommend mitigations for blocking the attacks that we present in this work. Nevertheless, the countermeasures cannot solve the fundamental problem - the management of the Internet resources should be revised to ensure that applying transactions cannot be done so easily and stealthily as is currently possible.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源