You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network Stack
Inon Kaplan, Ron Even, Amit Klein
Abstract
—This research is the first holistic analysis of the algorithmic security of the Google Fuchsia/gVisor network stack. Google Fuchsia is a new operating system developed by Google in a “clean slate” fashion. It is conjectured to eventually replace Android as an operating system for smartphones, tablets, and IoT devices. Fuchsia is already running in millions of Google Nest Hub consumer products. Google gVisor is an application kernel used by Google’s App Engine, Cloud Functions, Cloud ML Engine, Cloud Run, and Google Kubernetes Engine (GKE). Google Fuchsia uses the gVisor network stack code for its TCP/IP implementation. Wereportmultiple vulnerabilities in the algorithms used by Fuchsia/gVisor to populate network protocol header fields, specifically the TCP initial sequence number, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID fields. In our holistic analysis, we show how a combination of multiple attacks results in the exposure of a PRNG seed and a hashing key used to generate the above fields. This enables an attacker to predict future values of the fields, which facilitates several network attacks. Our work focuses on web-based device tracking based on the stability and relative uniqueness of the PRNG seed and the hashing key. We demonstrate our device tracking techniques over the Internet with browsers running on multiple Fuchsia devices, in multiple browser modes (regular/privacy), and over multiple networks (including IPv4 vs. IPv6). Our tests verify that device tracking for Fuchsia is practical and yields a reliable device ID. We conclude with recommendations on mitigating the attacks and their root causes. We reported our findings to Google, which issued CVEs and patches for the security vulnerabilities we disclosed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c8eed18-bb15-485e-b2b3-044141c14679Builds on9
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- JavaScript Template Attacks: Automatically Inferring Host Information for Targeted ExploitsMichael Schwarz, Florian Lackner, Daniel GrussNDSS 2019 · 57 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 34 citations
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 26 citations
Related papers
- Device Tracking via Linux's New TCP Source Port Selection AlgorithmMoshe Kol, Amit Klein, Yossi GiladUSENIX Security 2023
- Flaw Label: Exploiting IPv6 Flow LabelJonathan Berger, Amit Klein, Benny PinkasS&P 2020 · 11 citations
- From IP ID to Device ID and KASLR BypassAmit Klein, Benny PinkasUSENIX Security 2019 · 25 citations
- Bleem: Packet Sequence Oriented Fuzzing for Protocol ImplementationsZhengxiong Luo, Junze Yu, Feilong Zuo, Jianzhong Liu et al.USENIX Security 2023
- Call Me Back!: Attacks on System Server and System Apps in Android through Synchronous CallbackKai Wang, Yuqing Zhang, Peng LiuCCS 2016 · 22 citations
